Analytics Informational

Uncommon access to Microsoft Teams cookies files

Sensitive Microsoft Teams cookies files were accessed.

Module:
Identity Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Credentials from Password Stores (T1555) Steal Application Access Token (T1528)
Detector tags: Microsoft Teams
Attacker's goals:

Attacker may access credentials files and steal application access tokens to gain remote access.

Investigative actions:

Investigate the actor process to determine if it was used for legitimate purposes or malicious activity. Review the host for any additional unusual activity. Investigate the Graph API calls followed by the user that might be related.

Test period:
10 Minutes
Deduplication:
1 Day
1 variation:
  • Suspicious uncommon access to Microsoft Teams cookies files Low (parent: Informational)