Analytics
Informational
✕
Microsoft Teams enumeration activity
The Microsoft Graph API was used to enumerate Microsoft Teams channels in an Azure tenant.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Azure Audit Log, Microsoft Graph Logs
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Cloud Service Discovery (T1526)
Detector tags: Microsoft Graph Activity Logs Microsoft Teams
Attacker's goals:
To extract sensitive information stored in Microsoft Teams.
Investigative actions:
Determine which Teams channels were enumerated and whether they contained any sensitive information. Investigate the identity following actions.
- Test period:
- 10 Minutes
- Deduplication:
- 5 Days