Compromised Account Sends Passkey/SSO-Themed Teams Phishing (Lateral)
This rule monitors Microsoft Teams communications for keywords related to passkey or Single Sign-On (SSO) configuration, which are common themes in social engineering and credential harvesting attacks. It correlates these messages with Windows logon events (Event ID 4624) for the sender to identify potentially compromised accounts or active phishing attempts originating from within the environment.
Cortex XDR

