Skip to content

[New Rule] Microsoft 365 Teams External Access Enabled#661

Merged
bm11100 merged 6 commits intoelastic:mainfrom
bm11100:o365-external-access-enabled
Dec 8, 2020
Merged

[New Rule] Microsoft 365 Teams External Access Enabled#661
bm11100 merged 6 commits intoelastic:mainfrom
bm11100:o365-external-access-enabled

Conversation

@bm11100
Copy link
Contributor

@bm11100 bm11100 commented Nov 30, 2020

Issues

resolves #572

Summary

Identifies when external access is enabled in Microsoft Teams. External access lets Teams and Skype for Business users communicate with other users that are outside of your organization. An adversary may enable external access or add an allowed domain to exfiltrate data or maintain persistence in an environment.

Contributor checklist

@bm11100
Copy link
Contributor Author

bm11100 commented Nov 30, 2020

when #570 merges, the non-ecs-schema modification may no longer be needed. will confirm.

@bm11100 bm11100 changed the title [New Rule] O365 Teams External Access Enabled [New Rule] Microsoft 365 Teams External Access Enabled Dec 2, 2020
@bm11100 bm11100 requested review from dstepanic and removed request for threat-punter December 2, 2020 17:19
@bm11100
Copy link
Contributor Author

bm11100 commented Dec 2, 2020

I still needed the non-ecs-schema even after #570 merged @brokensound77

Copy link
Contributor

@dstepanic dstepanic left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, left minor comment

Copy link
Contributor

@brokensound77 brokensound77 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left a comment on the bad field, otherwise LGTM 👍

@bm11100 bm11100 merged commit d74b41c into elastic:main Dec 8, 2020
@bm11100 bm11100 deleted the o365-external-access-enabled branch December 8, 2020 21:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[New Rule] O365 Teams External Access Enabled

4 participants