kevmap

Log sources › saas:slack

saas:slack

Inverted view: what can be detected if this is the log you have. SaaS

6
channels
6
analytics
6
techniques
3
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Exported file or accessed admin API DC0069 Cloud Service Modification AN1162 1
OAuth token use by unknown app client_id accessing private channels or files DC0038 Application Log Content AN1427 1
chat.postMessage, files.upload, or discovery API calls involving token/credential regex DC0038 Application Log Content AN0310 1
conversations.history, files.list, users.info, audit_logs DC0038 Application Log Content AN1565 1
file_upload, message_send, message_click DC0038 Application Log Content AN0150 1
xternal DM or workspace invite preceding credential or approval actions DC0038 Application Log Content AN2034 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1213 Data from Information Repositoriescollection72
T1213.005 Messaging Applicationscollection00
T1528 Steal Application Access Tokencredential access141
T1534 Internal Spearphishinglateral movement00
T1552.008 Chat Messagescredential access00
T1684 Social Engineeringstealth00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2022-24086Adobe Commerce and Magento Open Source T1213 Mapped
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM) T1213 Mapped
CVE-2024-38475Apache HTTP Server T1528 Mapped