Defender-MessageEvents

ActionTypeTitleSampleRule
anyTeams message processedNY

any: Teams message processed

#
Table
MessageEvents

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
ThreadType (kusto rule field)eqchat2 ruleskusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

  • Detect Possible Teams BEC Attack by High Teams Recipients source: An external sender suddenly increasing the amount of internal users they are sending messages to, can indicate that external user being compromised and used for BEC Attacks. In these kind of attacks compromised accounts are used to send phishing links or attachments to users in business relationships.T1566

References #