{"id":"T1552.008","name":"Chat Messages","url":"https://attack.mitre.org/techniques/T1552/008","tactics":["credential-access"],"platforms":["SaaS","Office Suite"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0111","stix_id":"x-mitre-detection-strategy--a9b4dd72-07f2-4fd5-b46b-2fe9f6945f14","name":"Detect Unsecured Credentials Shared in Chat Messages","url":"https://attack.mitre.org/detectionstrategies/DET0111","analytics":[{"id":"AN0309","stix_id":"x-mitre-analytic--631da3e4-5ecd-4dc9-966a-1c2633f8f24c","name":"Analytic 0309","description":"Detection correlates message events in email and collaboration tools (e.g., Outlook, Teams) that contain regex-like patterns resembling credentials, API keys, or tokens. Anomalous forwarding or bulk copy activity of chat/email content containing secrets is flagged. Suspicious behavior includes users pasting secrets into direct messages or attaching config files with passwords.","url":"https://attack.mitre.org/detectionstrategies/DET0111#AN0309","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"MessageSend, MessageRead, or FileAttached events containing credential-like patterns","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"RegexPatterns","description":"Customizable credential-detection regex (e.g., API_KEY=, bearer token formats) depending on enterprise apps in use"},{"field":"AllowedDomains","description":"Exclude known trusted domains or automated system-to-system messages"},{"field":"TimeWindow","description":"Adjust correlation period for bulk credential sharing events"}],"live":true,"detection_strategies":["DET0111"],"techniques":["T1552.008"]},{"id":"AN0310","stix_id":"x-mitre-analytic--bafd38ad-aebd-40f1-9f17-bd63a1c74ba9","name":"Analytic 0310","description":"Detection monitors SaaS collaboration tools (e.g., Slack, Zoom, Jira) for messages or files containing credential-like patterns, or for suspicious API calls retrieving bulk chat histories by non-admin users. Identifies adversary behavior chains where chat logs are queried via APIs or integration bots to systematically extract sensitive material.","url":"https://attack.mitre.org/detectionstrategies/DET0111#AN0310","platforms":["SaaS"],"log_source_references":[{"name":"saas:slack","channel":"chat.postMessage, files.upload, or discovery API calls involving token/credential regex","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-slack"},{"name":"saas:okta","channel":"Unusual OAuth app requesting message-read scopes for Slack/Teams/Jira","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"saas-okta"}],"mutable_elements":[{"field":"IntegrationScope","description":"Tune to ignore known enterprise bots with message-read access (e.g., DLP scanners)"},{"field":"RegexPatterns","description":"Customizable regex for detecting secret formats (JWT, OAuth tokens, SSH keys)"},{"field":"UserContext","description":"Correlate with user role to filter developers vs standard users"}],"live":true,"detection_strategies":["DET0111"],"techniques":["T1552.008"]}],"live":true,"version":"1.0","techniques":["T1552.008"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}