Log sources › saas:slack
saas:slack
Inverted view: what can be detected if this is the log you have. SaaS
6
channels
6
analytics
6
techniques
3
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Exported file or accessed admin API |
DC0069 Cloud Service Modification | AN1162 | 1 |
OAuth token use by unknown app client_id accessing private channels or files |
DC0038 Application Log Content | AN1427 | 1 |
chat.postMessage, files.upload, or discovery API calls involving token/credential regex |
DC0038 Application Log Content | AN0310 | 1 |
conversations.history, files.list, users.info, audit_logs |
DC0038 Application Log Content | AN1565 | 1 |
file_upload, message_send, message_click |
DC0038 Application Log Content | AN0150 | 1 |
xternal DM or workspace invite preceding credential or approval actions |
DC0038 Application Log Content | AN2034 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1213 Data from Information Repositories | collection | 7 | 2 |
| T1213.005 Messaging Applications | collection | 0 | 0 |
| T1528 Steal Application Access Token | credential access | 14 | 1 |
| T1534 Internal Spearphishing | lateral movement | 0 | 0 |
| T1552.008 Chat Messages | credential access | 0 | 0 |
| T1684 Social Engineering | stealth | 0 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2022-24086 | Adobe Commerce and Magento Open Source | T1213 | Mapped |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile (EPMM) | T1213 | Mapped |
| CVE-2024-38475 | Apache HTTP Server | T1528 | Mapped |