elastic / elastic/detection-rules

[New Rule] A user has downloaded an excessive amount of files in Slack over a short period

Open
#4,137 3 comments 0 reactions 1 assignee Claimed by @brokensound77 View on GitHub
backlog Integration: Slack Rule: New Team: TRADE
Dominant language
Python
Stars
2.7k
Forks
696
Avg merge
4d 17h
Merged PRs (30d)
87

Description

### Description

A user has downloaded an excessive amount of files in Slack over a short period, which could indicate attempts to perform recon, discovery, or exfil.

This could potentially be considered as a BBR as well

Similar to internal: `ba20c1de-1728-4a59-9afa-b7e502d359a4`

### Target Ruleset

other

### Target Rule Type

Threshold

### Tested ECS Version

_No response_

### Query

* index: `logs-slack.audit*`
* query:

```sql
event.action:file_downloaded and
not slack.audit.entity.filetype:(image/* or video/* or application/vnd* or audio/* or "application/x-iwork-keynote-sffkey" or application/x-iwork-numbers-sffnumbers or application/msword or "application/pdf")
```

* threshold:
```
cardinality:
- field: slack.audit.entity.name
value: 4
field:
- user.email
- source.ip
value: 1
```
* timing: lookback: 30m, interval 15m

### New fields required in ECS/data sources for this rule?

_No response_

### Related issues or PRs

_No response_

### References

https://api.slack.com/admins/audit-logs-call

### Redacted Example Data

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.