Analytics BIOC
Informational
✕
External user added a link to a Microsoft Teams chat
An external user added a link to a Microsoft Teams chat.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Office 365 Audit
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Phishing (T1566)
Detector tags: Microsoft Teams
Attacker's goals:
Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.
Investigative actions:
Confirm that the external tenant and user are authorized to share links or files with users in the organization. Verify the content of the conversation and validate that there is no phishing attempt being made. Inspect links and URLs that have been sent in the conversation. Evaluate the external domain reputation. Review past communication from the external user. Follow further actions done by the account.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- An external user sent a link via Microsoft Teams with suspicious parameters Low (parent: Informational)