Fluency · Case Investigation · Executive Report

Phishing link clicked through Microsoft Teams: harper.morgan@acmeinc.com

Tenant expo (Acme Inc.) · Case username_harper.morgan@acmeinc.com_20260924

Critical Risk 8,800 (band > 8,000) Status New Incident Yes Window Sep 24, 2026, 12:03–12:21 UTC Rules 1 · Hits 1
8,800
Risk score (certainty it needs review)
1
Behavior rule fired
2
Underlying events captured
2
First-time flags (organization and user)
14 s
From the click to Microsoft removing the message
Executive summary

A phishing link hosted on OneDrive reached harper.morgan through Microsoft Teams around 12:03 UTC. At 12:13:44 the user clicked it and Microsoft Defender allowed the click. Fourteen seconds later Microsoft classified the message as phishing and removed it. The removal was too late to stop the click.

Fluency flagged this alert as the first of its kind in the organization and the first for this user, which is why it scored Critical. Our assessment: about 80% likely a real security issue. What remains unknown is whether the user entered a password or downloaded a file. The next step is to review this user's sign-ins and device activity after 12:13 UTC.

What Fluency's AI Assistant already concluded

Fluency AI Assistant triage · built on in this report

Escalate to Tier Two Validated Actionable Evidence quality: moderate

"Malicious URL click by harper.morgan@acmeinc.com was allowed at time of click and later flagged by MDO. No mitigation observed. Immediate escalation to Tier Two is recommended for containment, forensic triage, credential/session review, and tenant-wide remediation."

What happened: timeline

12:0012:0512:1012:1512:20 ~12:03 Delivered Teams message, OneDrive link 12:13:44 Clicked, allowed Defender Safe Links · High 12:13:58 Removed (+14 s) Phish, Malicious · quarantined Alerts raised 12:15 and 12:21

MITRE ATT&CK Inferred from signatures & activity

ReconResource Dev.Initial AccessExec­utionPersist­encePriv. Esc.Defense EvasionCred. Access?Discov­eryLateral Mvmt.Collec­tionC2Exfil­trationImpact

Filled: seen in the evidence. Dashed: possible, not yet evidenced (depends on whether credentials were entered).

TacticTechniqueEvidenceBasis
Initial AccessT1566.002 Spearphishing Link, or T1566.003 via ServicePhishing link on a OneDrive share, delivered through Microsoft Teamsactivity
ExecutionT1204.001 User Execution: Malicious LinkUser clicked; Safe Links allowed itsignature + activity
Credential AccessT1056.003 Web Portal Capture (possible)Not evidenced. A OneDrive-hosted phishing page commonly harvests credentials; no sign-in data after the clickinference only

The Fluency signature catalog for this tenant has no formal ATT&CK tags (0 of 20 signatures mapped), so every mapping above is an analyst inference.

What's in the records

Events by type

Malicious URL click detected 1 Phish message removed after delivery 1

Both are Microsoft 365 Security & Compliance alert events (AlertEntityGenerated). Only the click fired a Fluency behavior rule.

Source

2/2 Security & Compliance Center Office 365 audit (Audit.General)
ContextValue
Userharper.morgan@acmeinc.com · Member, not privileged
Delivery channelMicrosoft Teams; one delivery recorded (likely the only recipient)
Link1drv.ms/w/c/fe9610a0d0349cf8/IQCA6AZZWQ84QKxLupigsQsqAf-UuNXugCZfSoZEwy8ggRU
Click12:13:44 UTC from 92.98.243.x · Defender Safe Links outcome Allowed · severity High
Removal12:13:58 UTC · Success_MessageQuarantined · threat Phish, Malicious · hosted content filter policy
Risk flagsALERT_SEVERITY_HIGH ML_NEW_ALERT first time this alert has fired in the organization · ML_NEW_USER first time for this user
Sign-ins (prior 12 h)None recorded: enrichment gap
Device usedNot in the data: enrichment gap

What we alerted on

Behavior ruleScoreFlagsWhat it caught
Fluency_O365_SCC_​Threat_Management_​Alert_High_v28,800ALERT_SEVERITY_HIGH
ML_NEW_ALERT
ML_NEW_USER
A high-severity Microsoft Defender alert: the user clicked a URL later identified as malicious, and the click was allowed. New to the organization and to the user, so the score was amplified.

What we could have alerted on

Candidate ruleWhy it would help
Click before removalLink a "message removed after delivery" event to a click on the same link by the same user. Today the removal is informational and creates no behavior, so the case under-states that the user was exposed before cleanup.
Phishing through TeamsTreat Teams-delivered phish as its own signal. Many users trust chat more than email.
Trusted-host phishingRaise OneDrive and SharePoint share links that Microsoft classifies as phish; trusted domains get past URL reputation checks.
Suspicious sign-in after a malicious clickA new IP, device or MFA prompt for the same user within hours of the click. Needs Entra ID sign-in data, which is absent here.
Download or process after the clickEDR activity on the clicking device. Needs endpoint telemetry, which is absent here.

Verdict: real issue vs. benign

Real issue ~80%~15%5%

Red: likely a real issue. Green: likely benign. Gray: indeterminate.

Likely a real issue (~80%)

  • Microsoft classified the message Phish, Malicious and removed it; it wasn't just a reputation warning.
  • The user clicked and the click was allowed before removal.
  • OneDrive hosting and Teams delivery are a known way to get past email and URL filters.
  • First time this alert has fired in the organization, and first for this user: this isn't routine noise.
  • Fluency's AI triage independently validated it and escalated to Tier 2.

Likely benign (~15%)

  • Safe Links can misclassify legitimate OneDrive shares.
  • A click alone doesn't mean compromise: the user may have closed the page without entering anything.
  • There's no sign of follow-on activity in this data. That is absence of data, not proof: no sign-in or device records were present.

Recommended next steps

  1. Review Entra ID sign-ins for harper.morgan after 12:13 UTC: new IPs, devices or MFA prompts. If anything is unusual, revoke sessions and reset the password. This is the check most likely to settle the verdict.
  2. Check the device used for the click: EDR telemetry and any downloads. Clients with a Tenable One MCP can also check whether that endpoint is exposed or vulnerable, which is context Fluency doesn't hold.
  3. Block and report the OneDrive share, and confirm no other user received or clicked it.
  4. Ask the user what the page showed and whether they entered anything.
Method. Read-only investigation of tenant expo through the Fluency MSSP MCP: get_case, expand_case (2 records captured, retained to Oct 12, 2026) and describe_expanded_case (evidence marked sufficient), plus summarize_signature_attack_coverage. No case state, verdict or mapping was written to Fluency. ATT&CK mappings are inferred. The likelihood percentages are an analyst estimate, not a Fluency output. Times are UTC. Expo is a demonstration tenant: its records are sanitized replays of real activity, with the organization shown as Acme Inc. Prepared Sep 28, 2026.