Teams Client Activity from Potentially Compromised Account (Coverage-Limited)

Detects the execution of Microsoft Teams client processes on endpoints associated with user accounts that have already been flagged as compromised via authentication anomalies. This rule acts as a pivot and investigation tool for tracking potentially malicious activity within Teams on impacted hosts.