elastic / elastic/detection-rules
[New Rule] A user has downloaded an excessive amount of files in Slack over a short period
- Dominant language
- Python
- Stars
- 2.7k
- Forks
- 696
- Avg merge
- 4d 17h
- Merged PRs (30d)
- 87
Description
### Description
A user has downloaded an excessive amount of files in Slack over a short period, which could indicate attempts to perform recon, discovery, or exfil.
This could potentially be considered as a BBR as well
Similar to internal: `ba20c1de-1728-4a59-9afa-b7e502d359a4`
### Target Ruleset
other
### Target Rule Type
Threshold
### Tested ECS Version
_No response_
### Query
* index: `logs-slack.audit*`
* query:
```sql
event.action:file_downloaded and
not slack.audit.entity.filetype:(image/* or video/* or application/vnd* or audio/* or "application/x-iwork-keynote-sffkey" or application/x-iwork-numbers-sffnumbers or application/msword or "application/pdf")
```
* threshold:
```
cardinality:
- field: slack.audit.entity.name
value: 4
field:
- user.email
- source.ip
value: 1
```
* timing: lookback: 30m, interval 15m
### New fields required in ECS/data sources for this rule?
_No response_
### Related issues or PRs
_No response_
### References
https://api.slack.com/admins/audit-logs-call
### Redacted Example Data
_No response_
Contributor guide
Assessment
This issue has not been assessed yet.