Microsoft Defender for Office 365: New MessageContents table in Advanced Hunting for Microsoft Teams messages
🚨 The Signal: Microsoft Defender for Office 365 Advanced Hunting now includes a 'MessageContents' table for Microsoft Teams. This allows security teams to investigate threats by querying Teams message snippets and metadata, enhancing threat detection and response capabilities.
The Impact
Security analysts are affected, gaining enhanced visibility into Teams communications for threat investigation, reducing risk of undetected internal threats.
- Security Analysts: Gain new data for Teams threat investigations.
- Security Operations Teams: Improved ability to detect and respond to Teams-based threats.
- Incident Responders: Faster correlation of Teams activity with other security signals.
- Compliance Officers: Enhanced auditability of Teams communications during incidents.
The Action
- Review existing Advanced Hunting queries to incorporate the new 'MessageContents' table.
- Ensure security analysts have appropriate permissions for Advanced Hunting and message preview.
- Update incident response playbooks to leverage Teams message data in investigations.
- Communicate new capabilities to security operations and incident response teams.
Domain: Defender · Impact: medium · Workload: Microsoft Defender