Analytics BIOC Low

Uncommon access to Microsoft Teams credential files

Sensitive Microsoft Teams credential files were accessed.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials (T1552)
Attacker's goals:

Accessing these files is done by attackers to collect user credentials.

Investigative actions:

Investigate the actor process to determine if it was used for legitimate purposes or malicious activity.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Uncommon access to Microsoft Teams credential files by an unsigned and unpopular process Low