Suspicious Teams Message Soft Delete by Agent Identity via M365 Audit

PremiumReviewedSigma · Medium · v1
Product
m365
Service
audit
Author
HuntRule
Published
2026-06-09
Updated
2026-08-28

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects soft deletion of Teams channel messages, the cleanup step observed when a compromised Entra agent identity posts internal phishing links and then removes the evidence. Adversaries delete their own messages to hide internal spearphishing and slow investigation, so agent-driven message deletions in Teams warrant correlation with preceding message-send activity.

Related detections3 linkedT1070.008 — drag to rearrange
Suspicious Mail Send via Microsoft Graph by Application Identity via M365 Audit
Unusual Access to Windows Outlook Unistore Mail Data by Non-Standard Processes
Windows PowerShell Script Accessing Windows MailApp MailBox Data Path
Suspicious Teams Message Soft Delete by Agent Identity via M365 Audit
Pivot detection · T1070.008 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.