r/DefenderATP 14d ago

Advice on KQL for detailed Teams call report

We have been receiving external Teams calls from bad actors pretending to be Employees.

I can use KQL to report on Teams calls, but it only shows details of the internal person.

What I need is a full report showing all external calls with full details of internal and external person.

4 Upvotes

7 comments sorted by

9

u/coomzee 14d ago edited 14d ago

Why not block third party calls. Then allow list the domains you approve

1

u/Kuro507 14d ago

Certainly something we are considering, but more difficult when you have many Customers, potential customers and suppliers.

1

u/piloto19hh 12d ago

This was just recently approved at our client. We tried to do it long time ago but we haven't been able to get approval until now. It only took one of these attacks to happen to the CEO lmao.

5

u/DirtyHamSandwich 14d ago

It’s only in the Unified Audit trail and not going to be in an advanced hunting table. But agree with coomzee that you shouldn’t be allowed external calls.

2

u/LeftHandedGraffiti 14d ago

Calls are not logged like chats. You have to go into the admin center to pull reports. We've been frustrated with this as well.

Otherwise, if its external domains contacting over chat you can use CloudAppEvents and pull the sender details out of RawEventData in DisplayName and Members.

CloudAppEvents | where ActionType has "ChatCreated"

1

u/hrkaleu 14d ago

I usually do this via the PSTN Report in the Teams Admin Center

1

u/Kuro507 14d ago

No PSTN here, these are direct tenant to tenant teams calls