Browse Rules

Search and filter across all detection sources

62 rules

panther low python

Slack Organization Created

Detects when a Slack organization is created

panther medium python

Slack Organization Deleted

Detects when a Slack organization is deleted

panther low python

Slack Anomaly Detected

Passthrough for anomalies detected by Slack

panther high python

Slack EKM Slackbot Unenrolled

Detects when a workspace is longer enrolled in EKM

panther medium python

Slack App Added

Detects when a Slack App has been added to a workspace

panther medium python

Slack App Access Expanded

Detects when a Slack App has had its permission scopes expanded

panther high python

Slack User Privilege Escalation

Detects when a Slack user gains escalated privileges

panther medium python

Slack App Removed

Detects when a Slack App has been removed

panther high python

Slack IDP Configuration Changed

Detects changes to the identity provider (IdP) configuration for Slack organizations.

panther medium python

Slack Information Barrier Modified

Detects when a Slack information barrier is deleted/updated

panther medium python

Slack User Privileges Changed to User

Detects when a Slack account is changed to User from an elevated role.

sublime high mql

DLP: Slack Token

Detects messages containing Slack API tokens and webhooks.

sentinel low kql

SlackAudit - Empty User Agent

'This query shows connections to the Slack Workspace with empty User Agent.'

sublime low mql

Open redirect: Slack

Message contains use of Slack's open redirect but the sender is not Slack.

panther critical python

Slack Enterprise Key Management Unenrolled

Detects when Slack Enterprise Key Management (EKM) is unenrolled, removing customer-controlled encryption and reverting to Slack-managed keys. EKM allows organizations to store encryption keys externally (e.g., AWS KMS), ensuring data remains protected even from Slack infrastructure compromise. Unenrollment exposes all workspace data to decryption by Slack systems and violates compliance requirements for regulated industries.

panther high python

Slack SSO Settings Changed

Detects changes to Single Sign On (SSO) restrictions

anvilogic high spl

Slack: Multiple files downloaded from channel [splunk-slack]

This use-case will detect when a user downloads 10 or more files from a Slack channel in a 60 minute timeframe. Data harvesting from Slack has been observed by threat groups such as LAPSUS$ to obtain sensitive data

panther high python

Slack MFA Settings Changed

Detects changes to Multi-Factor Authentication requirements

panther high python

Slack Legal Hold Policy Modified

Detects changes to configured legal hold policies

elastic-protections high eql

Slack Workspace Files Accessed by Osascript

Identifies the Osascript process accessing sensitive Slack files. Adversaries can steal certain Slack files that allows them to log in to the Slack workspace as that user without a password in order to collect additional sensitive data or spy on the organization.

elastic-protections high eql

Slack Workspace Files Accessed by Unsigned or Untrusted Process

Identifies an untrusted or unsigned process accessing sensitive Slack files. Adversaries can steal certain Slack files that will allow them to log in to the Slack workspace as that user without a password in order to collect additional sensitive data or spy on the organization.

sentinel low kql

SlackAudit - Unknown User Agent

'Detects Slack workspace activity from unknown user agents by comparing recent UserAgentOriginal values against a 14d baseline of known user agents.'

sentinel medium kql

SlackAudit - Suspicious file downloaded.

'Detects potentialy suspicious downloads.'

sublime high mql

beta.DLP: Slack Access Token

Detects messages containing Slack access tokens.

panther high python

Slack EKM Config Changed

Detects when the logging settings for a workspace's EKM configuration has changed