SlackAudit - Public link created for file which can contain sensitive information.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Detects public links created for files that may contain sensitive data such as passwords, authentication tokens, secret keys, or private configuration files. Tune exclusions using the SlackAuditSensitiveFile_Allowlist_File and SlackAuditSensitiveFile_Allowlist_Account watchlists when known benign files or accounts generate expected public-link activity.

Attribute Value
Type Analytic Rule
Solution SlackAudit
ID 279316e8-8965-47d2-9788-b94dc352c853
Severity Medium
Status Available
Kind Scheduled
Tactics Exfiltration
Techniques T1048, T1567.002
Required Connectors SlackAuditAPI
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
SlackAuditNativePoller_CL 🔶 ? ?
SlackAuditV2_CL
SlackAudit_CL 🔶 ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to SlackAudit