External user added a link to a Microsoft Teams chat

Cortex XSIAM Analytics Alert Reference by Alert name

Product
Cortex XSIAM
Last date published
2026-01-04
Category
Analytics Alert Reference
Index by
Alert name

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

  • Requires:
    • Office 365 Audit

Detection Modules

Identity Threat Module

Detector Tags

Microsoft Teams

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Phishing (T1566)

Severity

Informational

Description

An external user added a link to a Microsoft Teams chat.

Attacker's Goals

Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.

Investigative actions

  • Confirm that the external tenant and user are authorized to share links or files with users in the organization.
  • Verify the content of the conversation and validate that there is no phishing attempt being made.
  • Inspect links and URLs that have been sent in the conversation.
  • Evaluate the external domain reputation.
  • Review past communication from the external user.
  • Follow further actions done by the account.

Variations

An external user sent a link via Microsoft Teams with suspicious parameters

Synopsis

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Phishing (T1566)

Severity

Low

Description

An external user sent a link with suspicious parameters in a Microsoft Teams conversation.

Attacker's Goals

Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.

Investigative actions

  • Confirm that the external tenant and user are authorized to share links or files with users in the organization.
  • Verify the content of the conversation and validate that there is no phishing attempt being made.
  • Inspect links and URLs that have been sent in the conversation.
  • Evaluate the external domain reputation.
  • Review past communication from the external user.
  • Follow further actions done by the account.