New Teams application published to the organization catalog

Cortex XDR Analytics Alert Reference by Alert name

Product
Cortex XDR
Last date published
2026-01-14
Category
Analytics Alert Reference
Index by
Alert name

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

  • Requires:
    • Office 365 Audit

Detection Modules

Identity Threat Module

Detector Tags

Microsoft Teams

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Account Manipulation (T1098)

Severity

Informational

Description

A new Teams application was published to the organization catalog.

Attacker's Goals

Attackers may leverage Teams applications to maintain persistent access to compromised Teams accounts.

Investigative actions

  • Confirm that the application was created by a certified and trusted entity.
  • Evaluate the permissions requested by the application to determine if they are excessive or unusual.
  • Determine if it is within the user's role to publish this type of application.
  • Correlate the alert with the sign-in event to get additional information on the identity performing the action.
  • Follow further actions done by the account.

Variations

A Microsoft Teams application was published to the organization catalog by an unusual user

Synopsis

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Account Manipulation (T1098)

Severity

Low

Description

A new Teams application was published to the organization catalog.

Attacker's Goals

Attackers may leverage Teams applications to maintain persistent access to compromised Teams accounts.

Investigative actions

  • Confirm that the application was created by a certified and trusted entity.
  • Evaluate the permissions requested by the application to determine if they are excessive or unusual.
  • Determine if it is within the user's role to publish this type of application.
  • Correlate the alert with the sign-in event to get additional information on the identity performing the action.
  • Follow further actions done by the account.