Bulk Teams Message Access via Graph API - T1213.005
This rule detects a potential data collection or exfiltration attempt in Microsoft Teams by identifying accounts that have accessed an abnormally high number of messages (more than 100 within a 5-minute window). This behavior may indicate an automated process or a compromised user account attempting to scrape internal communications.
Microsoft Sentinel (KQL)

