Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0111 — Detect Unsecured Credentials Shared in Chat Messages
DET0111

Detect Unsecured Credentials Shared in Chat Messages

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN0309 Analytic 0309
Office Suite

Detection correlates message events in email and collaboration tools (e.g., Outlook, Teams) that contain regex-like patterns resembling credentials, API keys, or tokens. Anomalous forwarding or bulk copy activity of chat/email content containing secrets is flagged. Suspicious behavior includes users pasting secrets into direct messages or attaching config files with passwords.

m365:unified MessageSend, MessageRead, or FileAttached events containing credential-like patterns
[RegexPatterns] Customizable credential-detection regex (e.g., API_KEY=, bearer token formats) depending on enterprise apps in use
[AllowedDomains] Exclude known trusted domains or automated system-to-system messages
[TimeWindow] Adjust correlation period for bulk credential sharing events
AN0310 Analytic 0310
SaaS

Detection monitors SaaS collaboration tools (e.g., Slack, Zoom, Jira) for messages or files containing credential-like patterns, or for suspicious API calls retrieving bulk chat histories by non-admin users. Identifies adversary behavior chains where chat logs are queried via APIs or integration bots to systematically extract sensitive material.

saas:slack chat.postMessage, files.upload, or discovery API calls involving token/credential regex saas:okta Unusual OAuth app requesting message-read scopes for Slack/Teams/Jira
[IntegrationScope] Tune to ignore known enterprise bots with message-read access (e.g., DLP scanners)
[RegexPatterns] Customizable regex for detecting secret formats (JWT, OAuth tokens, SSH keys)
[UserContext] Correlate with user role to filter developers vs standard users

Detected Techniques

1

Credential Access (1)

Details

MITRE ID
DET0111
STIX ID
x-mitre-detection-strategy--a9b4dd72-07f2-4fd5-b46b-2fe9f6945f14
Analytics
2
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.