A new Microsoft Teams app or bot was observed

이 페이지는 아직 한국어로 제공되지 않으며 번역 작업 중입니다. 번역에 관한 질문이나 의견이 있으시면 언제든지 저희에게 연락해 주십시오.

Goal

Detect when a new Microsoft 365 teams app or bot is installed as a means of establishing persistence.

Strategy

Monitor Microsoft 365 audit logs to look for events with an @evt.name value of AppInstalled, where the AddOnType has a value of 1 OR 4 and a new @AddOnName is observed.

According to Microsoft, the following values indicate the types of add-ons that exist:

  • 1 - Indicates a bot.
  • 2 - Indicates a connector.
  • 3 - Indicates a tab.

However, some add-ons use the value 4 for existing teams apps that could be potentially unapproved bots or applications that could be malicious.

Triage and response

  1. Determine if the user {{@usr.email}} intended to install {{@AddOnName}}.
  2. If {{@usr.email}} is not responsible for installing {{@AddOnName}}, investigate {{@usr.email}} for anomalous activity. If necessary, initiate your company’s incident response (IR) process.

Changelog

Updated rule name and query to include bots.