Analytics BIOC
Informational
✕
Microsoft Teams messages were exported from conversation
Microsoft Teams messages were exported from conversation.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Office 365 Audit
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data from Information Repositories: Messaging Applications (T1213.005)
Detector tags: Microsoft Teams
Attacker's goals:
Attackers may leverage message extraction from Microsoft Teams to obtain valuable information.
Investigative actions:
Confirm that the exported messages were extracted from a certified and trusted entity. Determine if it is within the user's role to extract messages from Microsoft Teams. Follow further actions done by the account and validate that the exported conversations were not sent to an untrusted entity.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Microsoft Teams messages were exported from conversation by a privileged user for the first time Low (parent: Informational)