10110010011101001011001101101110101018200.devFrom Enterprise.Systems
Slack logo

Slack

서비스 중생산성 및 협업

Slack 커넥터 — 읽기 전용, 에이전트리스

Scans channel and file sharing exposure, inventories installed apps, bots, and integrations and their OAuth token scopes (the AI-agent / shadow-AI surface), and audits the workspace security configuration (2FA enforcement, app-install policy, public file sharing, external Slack Connect channels).

8200.dev 대시보드에서 Slack을 직접 연결하십시오 — Marketplace가 필요하지 않습니다. 위의 Add to Slack을 사용하시거나 8200.dev → Connectors → Slack → Connect로 이동하십시오.

스캔 대상

  • Channel and file sharing metadata (public/external exposure — never message contents)
  • Installed apps / bots / integrations and their granted token scopes
  • Members, bots, and guests — including 2FA-registration status (never passwords)
  • Workspace configuration: 2FA enforcement, app-install approval, public file sharing, discovery

읽기 전용 모니터링 — 자동 교정을 활성화하고 쓰기 액세스를 별도로 허용하지 않는 한 Slack 데이터는 변경되지 않습니다.

보안 탐지 항목

25개의 탐지 규칙이 모든 Slack 스캔 시 실행됩니다. 각 탐지 항목에는 쉬운 언어로 된 설명, 이를 뒷받침하는 증거, 그리고 조치 단계가 함께 제공됩니다.

  • CRITICALPublic exposure

    Public link with edit/owner access

  • CRITICALExternal access

    External principal holds ownership

  • HIGHPublic exposure

    Public link share (link-only)

  • HIGHPublic exposure

    Public + web-discoverable share

  • HIGHExternal access

    External access to sensitive data

  • HIGHExternal access

    External collaborator with edit access

  • HIGHOver permission

    Sensitive resource editable org-wide

  • HIGHOver permission

    Broad group access to sensitive data

  • HIGHAI agent

    Service account with broad write access

  • HIGHAI agent

    AI agent with access to sensitive data

  • HIGHAI agent

    AI agent with edit/owner access

  • HIGHExternal access

    Access granted to a look-alike (typosquat) domain

  • HIGHIdentity

    Two-factor authentication is not enforced for all members

    When 2FA is not required workspace-wide, members can sign in with a password alone, and a single phished or reused credential grants an attacker full access to every channel that member can read. Slack exposes each member’s 2FA status (has_2fa); a material share of members without it means the policy is not enforced.

  • HIGHApplications

    Any member can install apps without admin approval

    When app installation is not restricted to admins, any employee can add a third-party app — including an AI assistant, GPT bot, or automation tool — and grant it access to channels and files with one click. This is the primary shadow-AI / over-broad-bot entry vector in Slack. App installs should route through an admin approval workflow.

  • MEDIUMOver permission

    Broad org-wide edit access (aggregate)

  • MEDIUMOver permission

    Resource with multiple owners

  • MEDIUMStale access

    Stale external read access

  • MEDIUMStale access

    Dormant privileged internal account

  • MEDIUMMisconfig

    Direct share breaks folder inheritance

  • MEDIUMApplications

    Apps installed by deactivated members still hold access

    An app installed by a member who has since been deactivated keeps its bot token and granted scopes — it can still read channels and files even though the person who authorized it, and could attest to why it exists, is gone. These orphaned installs are a quiet source of un-owned, un-reviewed access.

  • MEDIUMSharing

    Files are shared with public ("anyone with the link") URLs

    A file with a public link is reachable by anyone who has the URL — no Slack account, no workspace membership, no sign-in. One forwarded link leaks the file outside the org, and public links on files in private or sensitive channels are an especially sharp exposure.

  • MEDIUMSharing

    Channels are shared externally with other organizations (Slack Connect)

    Slack Connect channels are shared with one or more external organizations, so members of those orgs can read — and often post — in the channel. Each external channel is a data-egress path that needs an owner and a periodic review of which outside parties still belong there.

  • MEDIUMMisconfig

    Vendor AI-training data-contribution posture

  • LOWApplications

    More installed apps than the recommended review threshold

    A large installed-app surface is hard to govern: each app holds a token with scopes, and the more there are, the more likely one is over-permissioned, unused, or an unsanctioned automation. Keeping the count reviewed and pruned shrinks the attack surface.

  • LOWDiscovery

    Workspace can be discovered and joined by email domain

    When workspace discovery by email domain is on, anyone with an email at an approved domain can find and request (or auto-join) the workspace. On a large or shared domain this lets unvetted accounts into the org’s channels; new members should join by invitation or admin approval instead.

Slack 연결 방법

이 페이지에서 직접 Add to Slack 하시거나, 제품 내부의 8200.dev → Connectors → Slack → Connect에서 진행하십시오. 두 방식 모두 동일한 직접 OAuth 설치를 실행하며, 동일한 읽기 전용 권한을 사용합니다.

  1. 1단계

    이 페이지에서 Add to Slack을 클릭하십시오 — 직접 설치이며 Marketplace가 필요하지 않습니다.

  2. 2단계

    8200.dev에 로그인하시거나 몇 초 만에 무료 계정을 개설하십시오.

  3. 3단계

    워크스페이스를 선택하시고 Slack 자체 동의 화면에서 읽기 전용 권한을 승인하십시오.

  4. 4단계

    8200.dev가 자동으로 스캔하며 — 결과는 몇 분 이내에 표시됩니다.

8200.dev가 Slack으로 전송하는 내용

알림은 채널별 옵트인 방식이며, 설정 → 통합에서 선택하신 이벤트에 대해서만 전송됩니다. Slack에 게시될 수 있는 이벤트는 다음과 같습니다:

  • New security findingfinding.new
  • Finding resolvedfinding.resolved
  • Scan completedscan.completed
  • Scan failedscan.failed
  • Connector unhealthyconnector.unhealthy
  • Connector recoveredconnector.recovered
  • Approaching plan limitentitlement.warning

각 알림은 하나의 Slack 메시지입니다: 이벤트가 표시된 헤더, 심각도 색상 스트라이프, 주요 필드(심각도, 카테고리, 제목, 출처), 그리고 해당 탐지 항목으로 딥링크되는 “8200.dev 열기” 버튼으로 구성됩니다. 파일 내용이나 메시지 내용은 절대 포함되지 않습니다.

Slack 채널로 전달된 알림 예시(설명용 값).

8200.dev는 AI를 사용하여 보안 탐지 항목을 분석합니다. AI가 생성한 인사이트는 때때로 부정확할 수 있으므로, 모든 탐지 항목은 귀사의 보안팀이 검토해야 합니다.

몇 분 안에 첫 번째 소스를 연결하십시오 — 무료, 읽기 전용, 영업 상담 불필요.