Microsoft Teams Sensitive File Access By Uncommon Applications

 Original Source: [Sigma source]
Title: Microsoft Teams Sensitive File Access By Uncommon Applications
Status: test
Description:Detects file access attempts to sensitive Microsoft teams files (leveldb, cookies) by an uncommon process.
References:
  -https://www.bleepingcomputer.com/news/security/microsoft-teams-stores-auth-tokens-as-cleartext-in-windows-linux-macs/
  -https://www.vectra.ai/blog/undermining-microsoft-teams-security-by-mining-tokens
Author: @SerkinValery
Date: 2024-07-22
modified:None
Tags:
  • -'attack.credential-access'
  • -'attack.t1528'
Logsource:
  • product: windows
  • category: file_access
  • definition: Requirements: Microsoft-Windows-Kernel-File ETW provider
Detection:
  selection:
    FileName|contains:
      -'\Microsoft\Teams\Cookies'
      -'\Microsoft\Teams\Local Storage\leveldb'

  filter_main_legit_location:
    Image|endswith: '\Microsoft\Teams\current\Teams.exe'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: medium