10110010011101001011001101101110101018200.devFrom Enterprise.Systems
Slack logo

Slack

利用可能生産性とコラボレーション

Slack コネクター — 読み取り専用、エージェントレス

Scans channel and file sharing exposure, inventories installed apps, bots, and integrations and their OAuth token scopes (the AI-agent / shadow-AI surface), and audits the workspace security configuration (2FA enforcement, app-install policy, public file sharing, external Slack Connect channels).

Slack を 8200.dev ダッシュボードから直接接続できます。Marketplace は不要です。上部の Add to Slack をご利用いただくか、8200.dev → Connectors → Slack → Connect にお進みください。

スキャン対象

  • Channel and file sharing metadata (public/external exposure — never message contents)
  • Installed apps / bots / integrations and their granted token scopes
  • Members, bots, and guests — including 2FA-registration status (never passwords)
  • Workspace configuration: 2FA enforcement, app-install approval, public file sharing, discovery

読み取り専用での監視のため、自動修復を有効にして書き込みアクセスを別途付与しない限り、Slack のデータが変更されることはありません。

セキュリティ検出結果

25件の検出ルールが、Slackのスキャンごとに実行されます。各検出結果には、平易な言葉による説明、その根拠となる証拠、および修復手順が付属します。

  • CRITICALPublic exposure

    Public link with edit/owner access

  • CRITICALExternal access

    External principal holds ownership

  • HIGHPublic exposure

    Public link share (link-only)

  • HIGHPublic exposure

    Public + web-discoverable share

  • HIGHExternal access

    External access to sensitive data

  • HIGHExternal access

    External collaborator with edit access

  • HIGHOver permission

    Sensitive resource editable org-wide

  • HIGHOver permission

    Broad group access to sensitive data

  • HIGHAI agent

    Service account with broad write access

  • HIGHAI agent

    AI agent with access to sensitive data

  • HIGHAI agent

    AI agent with edit/owner access

  • HIGHExternal access

    Access granted to a look-alike (typosquat) domain

  • HIGHIdentity

    Two-factor authentication is not enforced for all members

    When 2FA is not required workspace-wide, members can sign in with a password alone, and a single phished or reused credential grants an attacker full access to every channel that member can read. Slack exposes each member’s 2FA status (has_2fa); a material share of members without it means the policy is not enforced.

  • HIGHApplications

    Any member can install apps without admin approval

    When app installation is not restricted to admins, any employee can add a third-party app — including an AI assistant, GPT bot, or automation tool — and grant it access to channels and files with one click. This is the primary shadow-AI / over-broad-bot entry vector in Slack. App installs should route through an admin approval workflow.

  • MEDIUMOver permission

    Broad org-wide edit access (aggregate)

  • MEDIUMOver permission

    Resource with multiple owners

  • MEDIUMStale access

    Stale external read access

  • MEDIUMStale access

    Dormant privileged internal account

  • MEDIUMMisconfig

    Direct share breaks folder inheritance

  • MEDIUMApplications

    Apps installed by deactivated members still hold access

    An app installed by a member who has since been deactivated keeps its bot token and granted scopes — it can still read channels and files even though the person who authorized it, and could attest to why it exists, is gone. These orphaned installs are a quiet source of un-owned, un-reviewed access.

  • MEDIUMSharing

    Files are shared with public ("anyone with the link") URLs

    A file with a public link is reachable by anyone who has the URL — no Slack account, no workspace membership, no sign-in. One forwarded link leaks the file outside the org, and public links on files in private or sensitive channels are an especially sharp exposure.

  • MEDIUMSharing

    Channels are shared externally with other organizations (Slack Connect)

    Slack Connect channels are shared with one or more external organizations, so members of those orgs can read — and often post — in the channel. Each external channel is a data-egress path that needs an owner and a periodic review of which outside parties still belong there.

  • MEDIUMMisconfig

    Vendor AI-training data-contribution posture

  • LOWApplications

    More installed apps than the recommended review threshold

    A large installed-app surface is hard to govern: each app holds a token with scopes, and the more there are, the more likely one is over-permissioned, unused, or an unsanctioned automation. Keeping the count reviewed and pruned shrinks the attack surface.

  • LOWDiscovery

    Workspace can be discovered and joined by email domain

    When workspace discovery by email domain is on, anyone with an email at an approved domain can find and request (or auto-join) the workspace. On a large or shared domain this lets unvetted accounts into the org’s channels; new members should join by invitation or admin approval instead.

Slackを接続する方法

このページから直接、または製品内の 8200.dev → Connectors → Slack → Connect から Slack を追加できます。どちらも同じ直接的な OAuth インストールを実行し、同じ読み取り専用の権限が適用されます。

  1. ステップ1

    このページの Add to Slack をクリックしてください。直接インストールで、Marketplace は不要です。

  2. ステップ2

    8200.dev にサインインするか、数秒で無料アカウントを開設してください。

  3. ステップ3

    ワークスペースを選択し、Slack 独自の同意画面で読み取り専用の権限を承認してください。

  4. ステップ4

    8200.dev が自動的にスキャンし、数分以内に結果が表示されます。

8200.devがSlackに送信する内容

アラートはオプトイン方式で、チャンネルごとに設定でき、Settings → Integrationsで選択したイベントについてのみ送信されます。Slackに投稿できるのは以下のイベントです:

  • New security findingfinding.new
  • Finding resolvedfinding.resolved
  • Scan completedscan.completed
  • Scan failedscan.failed
  • Connector unhealthyconnector.unhealthy
  • Connector recoveredconnector.recovered
  • Approaching plan limitentitlement.warning

各アラートは1件のSlackメッセージです。イベントを示すヘッダー、重大度を表すカラーストライプ、主要なフィールド(重大度、カテゴリ、タイトル、ソース)、および検出結果にディープリンクする「Open 8200.dev」ボタンで構成されます。ファイルの内容やメッセージの内容が送信されることは一切ありません。

Slackチャンネルに配信されるアラートの例(値は説明用のものです)。

8200.devはAIを使用してセキュリティの検出結果を分析します。AIが生成したインサイトは、まれに不正確な場合があります — すべての検出結果は、お客様のセキュリティチームによる確認が必要です。

最初のソースを数分で接続 — 無料・読み取り専用・営業担当への連絡不要。