A Microsoft Teams bot was added to a team

Cortex XSIAM Analytics Alert Reference by Alert name

Product
Cortex XSIAM
Last date published
2026-01-04
Category
Analytics Alert Reference
Index by
Alert name

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

  • Requires:
    • Office 365 Audit

Detection Modules

Identity Threat Module

Detector Tags

Microsoft Teams

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Cloud Application Integration (T1671)

Severity

Informational

Description

A user added a bot to a team in Microsoft Teams.

Attacker's Goals

Attackers may leverage Teams bots to maintain persistent access to compromised Teams accounts.

Investigative actions

  • Confirm that the bot was created by a certified and trusted entity.
  • Evaluate the permissions requested by the bot to determine if they are excessive or unusual.
  • Determine if it is within the user's role to add bots to teams.
  • Follow further actions done by the account.