A new Microsoft Teams app or bot was observed

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Goal

Detect when a new Microsoft 365 teams app or bot is installed as a means of establishing persistence.

Strategy

Monitor Microsoft 365 audit logs to look for events with an @evt.name value of AppInstalled, where the AddOnType has a value of 1 OR 4 and a new @AddOnName is observed.

According to Microsoft, the following values indicate the types of add-ons that exist:

  • 1 - Indicates a bot.
  • 2 - Indicates a connector.
  • 3 - Indicates a tab.

However, some add-ons use the value 4 for existing teams apps that could be potentially unapproved bots or applications that could be malicious.

Triage and response

  1. Determine if the user {{@usr.email}} intended to install {{@AddOnName}}.
  2. If {{@usr.email}} is not responsible for installing {{@AddOnName}}, investigate {{@usr.email}} for anomalous activity. If necessary, initiate your company’s incident response (IR) process.

Changelog

Updated rule name and query to include bots.