Slack Detection Pack
28 detection rules for Slack Enterprise Grid audit logs — covering file exfiltration to external users, OAuth app threats, workspace admin abuse, and C2 over Slack. One-click activation.
Pack summary
- Detection rules
- 28
- Critical severity
- 7
- Requires
- Enterprise Grid
- ATT&CK techniques
- 9
What's included
28 rules across 5 threat categories for Slack security threats.
File uploads to external users, channel exports, personal data exports, Connect channel abuse.
Workspace owner grants, DLP disable, EMM disable, retention policy reduction.
App installation with sensitive scopes, SCIM token creation, incoming webhooks.
Login from new country, SAML SSO bypass, API token from unusual IP.
Audit log API access removal, EKM key revocation.
Detection rules (20 of 28 shown)
Showing 20 representative rules. All 28 rules activate with one click.
| Rule name | Severity |
|---|---|
| Slack File Upload — Sensitive Extension to External User | High |
| Slack Workspace Owner Role Granted | Critical |
| Slack OAuth App Installed with DND / Message History Scope | High |
| Slack External Member Added to Private Channel | High |
| Slack Channel Export Initiated | Critical |
| Slack Guest Account Invited to Sensitive Workspace | High |
| Slack Workspace Discovery Mode Enabled | Medium |
| Slack EMM (Mobile Device Management) Disabled | High |
| Slack SCIM Token Created — Provisioning API Access | High |
| Slack DLP Policy Disabled | Critical |
| Slack User Account Deactivated by Non-Admin | High |
| Slack Anomalous Message Export by User | High |
| Slack Incoming Webhook Created to External URL | Medium |
| Slack Sign-In from New Country | High |
| Slack API Token Accessed by Unusual IP | High |
| Slack Retention Policy Reduced — Evidence Preservation Concern | Medium |
| Slack Enterprise Key Management — Encryption Key Revoked | Critical |
| Slack Admin Approved Workspace App — No Security Review | Medium |
| Slack Audit Log API Disabled or Access Removed | Critical |
| Slack User Signed In with SAML Bypass (Non-SSO Auth) | High |
Prerequisites
- Slack Enterprise Grid subscription (Audit Logs API is not available on lower tiers)
- Slack app installed with audit:read OAuth scope on an org-level service account
- Slack Enterprise Key Management (optional) for EKM-related detections
- SCIM provisioning configured if SCIM token monitoring is required
Slack Detection Pack: frequently asked questions
What Slack log sources does this detection pack use?
The Slack detection pack uses the Slack Audit Logs API, which is available to Slack Enterprise Grid customers. The API provides events for workspace configuration changes, user authentication, file uploads, app installations, and member changes. ManySignal connects via an installed Slack app with audit:read scope on a dedicated service account.
Do I need Slack Enterprise Grid for this detection pack?
Yes. The Slack Audit Logs API requires Slack Enterprise Grid. Organisations on Business+ or Pro plans do not have access to the Audit Logs API. For non-Grid customers, some monitoring is possible via SCIM provisioning events and Slack Workflow notifications, but comprehensive audit log coverage requires Enterprise Grid.
How does ManySignal detect insider threat patterns in Slack?
Insider threat detection in Slack focuses on pre-departure data staging: anomalous personal data exports, bulk file downloads to DMs with external contacts, and joining high-value channels outside the user's normal scope. ManySignal correlates these patterns with HR system offboarding events (when integrated) to increase confidence.
Can ManySignal detect C2 over Slack?
Yes. Slack is increasingly used as a C2 channel (T1102). ManySignal detects C2-over-Slack by monitoring for: application-layer Slack API calls from hosts that do not normally use Slack, unusual Slack API bot token usage from production server IP ranges, and Slack webhook callbacks from unexpected internal systems.
How does ManySignal handle Slack Connect channels?
Slack Connect channels (cross-workspace channels with external organisations) are monitored through the Audit Logs API. File uploads, user additions, and message activity in Connect channels are treated with elevated sensitivity — Connect channels bridge two security perimeters and are a common data exfiltration vector.
Detect Slack data exfiltration and insider threats
28 Slack detection rules covering file exfiltration, channel exports, OAuth app threats, and C2-over-Slack patterns for Enterprise Grid customers.