Slack
Telemetry Evidence
These values show how indexed rules identify Slack telemetry.Kusto
SlackAudit Panther
Slack.AuditLogs slack
Detection Rules
Kusto #
- SlackAudit - Empty User Agent source low: 'This query shows connections to the Slack Workspace with empty User Agent.'
T1133 - SlackAudit - Multiple archived files uploaded in short period of time source low: 'This query helps to detect when a user uploads multiple archived files in short period of time.'
T1567 - SlackAudit - Multiple failed logins for user source medium: 'Identifies multiple failed Slack logins for a user account within a short time window, which may indicate password guessing or brute-force activity.'
T1110 - SlackAudit - Public link created for file which can contain sensitive information. source medium: 'Detects public links created for files that may contain sensitive data such as passwords, authentication tokens, secret keys, or private configuration files. Tune exclusions using the SlackAuditSensitiveFile_Allowlist_File and SlackAuditSensitiveFile_Allowlist_Account watchlists when known benign files or accounts generate expected public-link activity.'
T1048,T1567,T1567.002 - SlackAudit - Suspicious file downloaded. source medium: 'Detects potentialy suspicious downloads.'
T1189 - SlackAudit - Unknown User Agent source low: 'Detects Slack workspace activity from unknown user agents by comparing recent UserAgentOriginal values against a 14d baseline of known user agents.'
T1071,T1071.001 - SlackAudit - User email linked to account changed. source medium: 'Detects when user email linked to account changes.'
T1078 - SlackAudit - User login after deactivated. source medium: 'Detects when a Slack user account was deactivated and the same user identity later authenticated again within the detection window, which may indicate account reactivation, unauthorized access, or use of a deactivated account. Analyst triage should review the deactivation time, subsequent login time, EntityUserEmail, and EntityUserId to determine whether the login was expected. This rule uses the SlackAuditAPI connector and SlackAudit_CL data type.'
T1078,T1078.004 - SlackAudit - User role changed to admin or owner source low: 'This query detects Slack audit events where a user role is changed to admin or owner, indicating potential privilege escalation or persistence activity. It monitors role change actions in Slack audit logs and maps the affected user as the primary account entity for investigation.'
T1078,T1098
Panther #
- Slack Anomaly Detected source low: Passthrough for anomalies detected by Slack
T1071 - Slack App Access Expanded source medium: Detects when a Slack App has had its permission scopes expanded
T1098 - Slack App Added source medium: Detects when a Slack App has been added to a workspace
T1505 - Slack App Removed source medium: Detects when a Slack App has been removed
T1070.009,T1489 - Slack Denial of Service via Session Invalidation source critical: Detects potential DoS attacks via excessive session invalidation when administrators reset user sessions 60+ times within 24 hours. Repeated session termination prevents users from maintaining Slack access, disrupting communication and productivity. Legitimate session resets for incident response or troubleshooting typically occur 1-3 times, so reaching the 60-event threshold indicates malicious intent.
T1499.003 - Slack DLP Modified source high: Detects when a Data Loss Prevention (DLP) rule has been deactivated or a violation has been deleted
T1070,T1685 - Slack EKM Config Changed source high: Detects when the logging settings for a workspace's EKM configuration has changed
T1685.002 - Slack EKM Slackbot Unenrolled source high: Detects when a workspace is longer enrolled in EKM
T1489 - Slack Enterprise Key Management Unenrolled source critical: Detects when Slack Enterprise Key Management (EKM) is unenrolled, removing customer-controlled encryption and reverting to Slack-managed keys. EKM allows organizations to store encryption keys externally (e.g., AWS KMS), ensuring data remains protected even from Slack infrastructure compromise. Unenrollment exposes all workspace data to decryption by Slack systems and violates compliance requirements for regulated industries.
T1530,T1567,T1600 - Slack IDP Configuration Changed source high: Detects changes to the identity provider (IdP) configuration for Slack organizations.
T1556
Show 12 more
- Slack Information Barrier Modified source medium: Detects when a Slack information barrier is deleted/updated
T1685 - Slack Legal Hold Policy Modified source high: Detects changes to configured legal hold policies
T1685 - Slack MFA Settings Changed source high: Detects changes to Multi-Factor Authentication requirements
T1556.006 - Slack Microsoft Intune Mobile Device Management Disabled source critical: Detects when Microsoft Intune MDM integration is disabled for Slack, removing mobile security controls and enabling data exfiltration via unmanaged devices. Intune enforces policies preventing copy/paste to unmanaged apps, requires device encryption, blocks jailbroken devices, and enables remote wipe. Disabling these controls allows unrestricted Slack access from personal or compromised devices without security restrictions.
T1567,T1685 - Slack Organization Created source low: Detects when a Slack organization is created
T1136 - Slack Organization Deleted source medium: Detects when a Slack organization is deleted
T1531 - Slack Potentially Malicious File Shared source critical: Detects when Slack's automated security scanning identifies malicious files uploaded to the workspace, indicating malware delivery or phishing attempts. Slack scans for executable malware, ransomware, phishing documents, malicious scripts, and files matching threat actor signatures. This detection indicates compromised accounts, insider threats, or successful phishing attacks where users uploaded infected files.
T1204.002,T1486,T1566.001 - Slack Primary Owner Transferred source critical: Detects Slack Primary Owner transfers, representing the highest administrative privilege change with absolute control over workspace settings, security, billing, and data access. Primary Owners can add/remove all admins, delete entire workspaces, and transfer ownership. Unauthorized transfers indicate account compromise, insider threats, or hostile takeovers that could lead to permanent data loss or complete security control loss.
T1078.004,T1098,T1531 - Slack Private Channel Made Public source high: Detects when a channel that was previously private is made public
T1098,T1222,T1567 - Slack SSO Settings Changed source high: Detects changes to Single Sign On (SSO) restrictions
T1556 - Slack User Privilege Escalation source high: Detects when a Slack user gains escalated privileges
T1098.003 - Slack User Privileges Changed to User source medium: Detects when a Slack account is changed to User from an elevated role.
T1531