SlackAudit - Failed logins with unknown username

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This query identifies Slack failed login attempts where the username has not been observed in successful login activity during the baseline period.

Attribute Value
Type Hunting Query
Solution SlackAudit
ID b62b5a97-41e5-47cb-9b90-aa079f65f0c0
Severity Medium
Tactics CredentialAccess
Techniques T1110, T1110.003
Required Connectors SlackAuditAPI
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
SlackAuditNativePoller_CL 🔶 ? ?
SlackAuditV2_CL
SlackAudit_CL 🔶 ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to SlackAudit