Analytics BIOC
Informational
✕
A Microsoft Teams bot was added to a team
A user added a bot to a team in Microsoft Teams.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Office 365 Audit
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Cloud Application Integration (T1671)
Detector tags: Microsoft Teams
Attacker's goals:
Attackers may leverage Teams bots to maintain persistent access to compromised Teams accounts.
Investigative actions:
Confirm that the bot was created by a certified and trusted entity. Evaluate the permissions requested by the bot to determine if they are excessive or unusual. Determine if it is within the user's role to add bots to teams. Follow further actions done by the account.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day