SlackAudit - Downloaded files stats

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This hunt highlights Slack users with the highest file-download volume over the last 24 hours to help identify unusual collection or staging activity.

Attribute Value
Type Hunting Query
Solution SlackAudit
ID 7865b00c-26c8-46db-9422-bb9e4ee696ac
Severity Medium
Tactics InitialAccess, Collection
Techniques T1189, T1133, T1213, T1119
Required Connectors SlackAuditAPI
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
SlackAuditNativePoller_CL 🔶 ? ?
SlackAuditV2_CL
SlackAudit_CL 🔶 ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to SlackAudit