{"id":"25cde13e-8e20-4c29-b949-4e795b76f16f","title":"Suspicious Teams Application Related ObjectAcess Event","description":"Detects an access to authentication tokens and accounts of Microsoft Teams desktop application.","author":"@SerkinValery","status":"test","level":"high","date":"2022-09-16","modified":"","tags":["attack.credential-access","attack.t1528"],"technique_ids":["T1528"],"logsource":{"product":"windows","service":"security"},"falsepositives":["Unknown"],"references":["https://www.bleepingcomputer.com/news/security/microsoft-teams-stores-auth-tokens-as-cleartext-in-windows-linux-macs/","https://www.vectra.ai/blogpost/undermining-microsoft-teams-security-by-mining-tokens"],"source_path":"rules/windows/builtin/security/win_security_teams_suspicious_objectaccess.yml","source_sha256":"2249d34fa404582464a43a7599048194e8f8af52ed560792d24bfb5f212458c7","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/security/win_security_teams_suspicious_objectaccess.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Suspicious Teams Application Related ObjectAcess Event\nid: 25cde13e-8e20-4c29-b949-4e795b76f16f\nstatus: test\ndescription: Detects an access to authentication tokens and accounts of Microsoft Teams desktop application.\nreferences:\n    - https://www.bleepingcomputer.com/news/security/microsoft-teams-stores-auth-tokens-as-cleartext-in-windows-linux-macs/\n    - https://www.vectra.ai/blogpost/undermining-microsoft-teams-security-by-mining-tokens\nauthor: '@SerkinValery'\ndate: 2022-09-16\ntags:\n    - attack.credential-access\n    - attack.t1528\nlogsource:\n    product: windows\n    service: security\ndetection:\n    selection:\n        EventID: 4663\n        ObjectName|contains:\n            - '\\Microsoft\\Teams\\Cookies'\n            - '\\Microsoft\\Teams\\Local Storage\\leveldb'\n    filter:\n        ProcessName|contains: '\\Microsoft\\Teams\\current\\Teams.exe'\n    condition: selection and not filter\nfalsepositives:\n    - Unknown\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1528","id":"T1528","name":"Steal Application Access Token","page":"techniques/enterprise/T1528/"}],"data_path":"data/detection-rules/25cde13e-8e20-4c29-b949-4e795b76f16f.json","kind":"sigma"}
