UNC6692 Teams External Invitation Flood to Single Internal User
Detects a suspicious spike in Microsoft Teams external meeting or chat invitations directed at a single user within a 30-minute window. This behavior is consistent with UNC6692 tactics, where attackers impersonate internal IT helpdesk staff via Teams to perform vishing and social engineering attacks.
Splunk (SPL)

