Suspicious File Event With Teams Objects (6902955a-01b7-432c-b32a-6f5f81d8f624)
Detects an access to authentication tokens and accounts of Microsoft Teams desktop application.
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Steal Application Access Token - T1528 (890c9858-598c-401d-a4d5-c67ebcdd703a) | Attack Pattern | Suspicious File Event With Teams Objects (6902955a-01b7-432c-b32a-6f5f81d8f624) | Sigma-Rules | 1 |