Analytics Informational

User exported multiple messages in Microsoft Teams via Graph API

A user exported multiple messages in Microsoft Teams via Graph API.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Office 365 Audit
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data from Information Repositories: Messaging Applications (T1213.005)
Detector tags: Microsoft Teams
Attacker's goals:

Attackers may leverage messages extraction from Microsoft Teams to collect sensitive data.

Investigative actions:

Confirm that the exported messages were extracted from a certified and trusted entity. Determine if it is within the user's role to extract messages from Microsoft Teams. Follow further actions done by the account and validate that the exported conversations were not sent to an untrusted entity.

Test period:
1 Hour
Deduplication:
1 Day
3 variations:
  • User exported multiple chats in Microsoft Teams via Graph API Low (parent: Informational)
  • User exported multiple messages in Microsoft Teams via Graph API by a privileged user for the first time Low (parent: Informational)
  • User exported multiple messages in Microsoft Teams via Graph API from a first seen ASN Low (parent: Informational)