Defender-MessageEvents

ActionTypeTitleSampleRule
anyTeams message processedNY

any: Teams message processed

#
Table
MessageEvents

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
ThreadType2 detection rulesKusto
ThreatTypes1 detection ruleKusto

Detection Patterns #

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
ThreadType (kusto rule field)eqchat2 ruleskusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

  • Detect Possible Teams BEC Attack by High Teams Recipients source: An external sender suddenly increasing the amount of internal users they are sending messages to, can indicate that external user being compromised and used for BEC Attacks. In these kind of attacks compromised accounts are used to send phishing links or attachments to users in business relationships.T1566

References #