elastic / elastic/detection-rules

[New Rule][BBR] A user previewed a Slack channel without joining

Open
#4,135 1 comment 0 reactions 1 assignee Claimed by @brokensound77 View on GitHub
backlog Integration: Slack Rule: New Team: TRADE
Dominant language
Python
Stars
2.7k
Forks
696
Avg merge
4d 17h
Merged PRs (30d)
87

Description

### Description

Detects when a user previews a Slack channel and does not join within a minute, which could be indicative of performing recon or attempting to locate sensitive information.

### Target Ruleset

other

### Target Rule Type

Event Correlation (EQL)

### Tested ECS Version

_No response_

### Query

Must first set the `event_category_override` to `slack.audit.entity.entity_type`

```sql
sequence by user.email, slack.audit.entity.name with maxspan=60s
[channel where event.action == "public_channel_preview"]
![channel where event.action == "user_channel_join"]
```

### New fields required in ECS/data sources for this rule?

`slack.*`

### Related issues or PRs

_No response_

### References

https://api.slack.com/admins/audit-logs-call

### Redacted Example Data

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.