Potentially Suspicious Command Targeting Teams Sensitive Files — Detection Rule

Detects a commandline containing references to the Microsoft Teams database or cookies files from a process other than Teams. The database might contain authentication tokens and other sensitive information about the logged in accounts.

Read the full analysis on IntelFusions