Slack
مباشرالإنتاجية والتعاونموصّل Slack — للقراءة فقط، بدون وكيل
Scans channel and file sharing exposure, inventories installed apps, bots, and integrations and their OAuth token scopes (the AI-agent / shadow-AI surface), and audits the workspace security configuration (2FA enforcement, app-install policy, public file sharing, external Slack Connect channels).
اربط Slack مباشرةً من لوحة تحكم 8200.dev الخاصة بك — دون الحاجة إلى Marketplace. استخدم Add to Slack أعلاه، أو انتقل إلى 8200.dev ← Connectors ← Slack ← Connect.
ما الذي نفحصه
- Channel and file sharing metadata (public/external exposure — never message contents)
- Installed apps / bots / integrations and their granted token scopes
- Members, bots, and guests — including 2FA-registration status (never passwords)
- Workspace configuration: 2FA enforcement, app-install approval, public file sharing, discovery
مراقبة بصلاحية القراءة فقط — لا يتغيّر شيء في بيانات Slack الخاصة بك ما لم تُفعّل المعالجة التلقائية وتمنح وصول الكتابة بشكل منفصل.
النتائج الأمنية
يتم تشغيل 25 قاعدة كشف في كل فحص لـ Slack. تأتي كل نتيجة مع شرح بلغة واضحة، والأدلة التي تدعمها، وخطوات المعالجة.
- CRITICALPublic exposure
Public link with edit/owner access
- CRITICALExternal access
External principal holds ownership
- HIGHPublic exposure
Public link share (link-only)
- HIGHPublic exposure
Public + web-discoverable share
- HIGHExternal access
External access to sensitive data
- HIGHExternal access
External collaborator with edit access
- HIGHOver permission
Sensitive resource editable org-wide
- HIGHOver permission
Broad group access to sensitive data
- HIGHAI agent
Service account with broad write access
- HIGHAI agent
AI agent with access to sensitive data
- HIGHAI agent
AI agent with edit/owner access
- HIGHExternal access
Access granted to a look-alike (typosquat) domain
- HIGHIdentity
Two-factor authentication is not enforced for all members
When 2FA is not required workspace-wide, members can sign in with a password alone, and a single phished or reused credential grants an attacker full access to every channel that member can read. Slack exposes each member’s 2FA status (has_2fa); a material share of members without it means the policy is not enforced.
- HIGHApplications
Any member can install apps without admin approval
When app installation is not restricted to admins, any employee can add a third-party app — including an AI assistant, GPT bot, or automation tool — and grant it access to channels and files with one click. This is the primary shadow-AI / over-broad-bot entry vector in Slack. App installs should route through an admin approval workflow.
- MEDIUMOver permission
Broad org-wide edit access (aggregate)
- MEDIUMOver permission
Resource with multiple owners
- MEDIUMStale access
Stale external read access
- MEDIUMStale access
Dormant privileged internal account
- MEDIUMMisconfig
Direct share breaks folder inheritance
- MEDIUMApplications
Apps installed by deactivated members still hold access
An app installed by a member who has since been deactivated keeps its bot token and granted scopes — it can still read channels and files even though the person who authorized it, and could attest to why it exists, is gone. These orphaned installs are a quiet source of un-owned, un-reviewed access.
- MEDIUMSharing
Files are shared with public ("anyone with the link") URLs
A file with a public link is reachable by anyone who has the URL — no Slack account, no workspace membership, no sign-in. One forwarded link leaks the file outside the org, and public links on files in private or sensitive channels are an especially sharp exposure.
- MEDIUMSharing
Channels are shared externally with other organizations (Slack Connect)
Slack Connect channels are shared with one or more external organizations, so members of those orgs can read — and often post — in the channel. Each external channel is a data-egress path that needs an owner and a periodic review of which outside parties still belong there.
- MEDIUMMisconfig
Vendor AI-training data-contribution posture
- LOWApplications
More installed apps than the recommended review threshold
A large installed-app surface is hard to govern: each app holds a token with scopes, and the more there are, the more likely one is over-permissioned, unused, or an unsanctioned automation. Keeping the count reviewed and pruned shrinks the attack surface.
- LOWDiscovery
Workspace can be discovered and joined by email domain
When workspace discovery by email domain is on, anyone with an email at an approved domain can find and request (or auto-join) the workspace. On a large or shared domain this lets unvetted accounts into the org’s channels; new members should join by invitation or admin approval instead.
Related guide
كيفية ربط Slack
أضف إلى Slack مباشرةً من هذه الصفحة، أو من داخل المنتج عبر 8200.dev ← Connectors ← Slack ← Connect. كلاهما يشغّل تثبيت OAuth المباشر نفسه، بالأذونات نفسها للقراءة فقط.
الخطوة 1
انقر على Add to Slack في هذه الصفحة — التثبيت المباشر، دون الحاجة إلى Marketplace.
الخطوة 2
سجّل الدخول إلى 8200.dev، أو افتح حسابًا مجانيًا في ثوانٍ.
الخطوة 3
اختر مساحة العمل الخاصة بك ووافق على أذونات القراءة فقط على شاشة الموافقة الخاصة بـ Slack.
الخطوة 4
يُجري 8200.dev الفحص تلقائيًا — تظهر النتائج خلال دقائق.
ما الذي يرسله 8200.dev إلى Slack
التنبيهات اختيارية، لكل قناة على حدة، ولا تُرسَل إلا للأحداث التي تختارها في Settings ← Integrations. هذه هي الأحداث التي يمكن نشرها على Slack:
- New security finding
finding.new - Finding resolved
finding.resolved - Scan completed
scan.completed - Scan failed
scan.failed - Connector unhealthy
connector.unhealthy - Connector recovered
connector.recovered - Approaching plan limit
entitlement.warning
كل تنبيه هو رسالة Slack واحدة: ترويسة تحتوي على الحدث، وشريط لوني يدل على مستوى الخطورة، والحقول الرئيسية (الخطورة، الفئة، العنوان، المصدر) وزر “Open 8200.dev” يرتبط مباشرةً بالاكتشاف. لا يتضمن أبدًا محتويات الملفات، ولا محتويات الرسائل.
8200.devapp3:42 PM
🔴 New security finding
🔴 New security finding
- severity:
- HIGH
- category:
- public_exposure
- title:
- Public link: Q3 board deck.pdf
- source:
- Google Workspace
يستخدم 8200.dev الذكاء الاصطناعي لتحليل الاكتشافات الأمنية. قد تكون الرؤى المُولَّدة بالذكاء الاصطناعي غير دقيقة أحيانًا — ينبغي مراجعة جميع الاكتشافات من قِبل فريق الأمن لديك.
اربط مصدرك الأول في دقائق — مجاناً، للقراءة فقط، دون الحاجة إلى مكالمة مبيعات.