Potentially Suspicious Command Targeting Teams Sensitive Files

 Original Source: [Sigma source]
Title: Potentially Suspicious Command Targeting Teams Sensitive Files
Status: test
Description:Detects a commandline containing references to the Microsoft Teams database or cookies files from a process other than Teams. The database might contain authentication tokens and other sensitive information about the logged in accounts.
References:
  -https://www.bleepingcomputer.com/news/security/microsoft-teams-stores-auth-tokens-as-cleartext-in-windows-linux-macs/
  -https://www.vectra.ai/blogpost/undermining-microsoft-teams-security-by-mining-tokens
Author: @SerkinValery
Date: 2022-09-16
modified:2023-12-18
Tags:
  • -'attack.credential-access'
  • -'attack.t1528'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection:
    CommandLine|contains:
      -'\Microsoft\Teams\Cookies'
      -'\Microsoft\Teams\Local Storage\leveldb'

  filter_main_legit_locations:
    Image|endswith: '\Microsoft\Teams\current\Teams.exe'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: medium