10110010011101001011001101101110101018200.devFrom Enterprise.Systems
免费开始
Slack logo

Slack

已上线生产力与协作

Slack 连接器——只读、无代理

Scans channel and file sharing exposure, inventories installed apps, bots, and integrations and their OAuth token scopes (the AI-agent / shadow-AI surface), and audits the workspace security configuration (2FA enforcement, app-install policy, public file sharing, external Slack Connect channels).

直接从您的 8200.dev 仪表板连接 Slack——无需通过 Marketplace。请使用上方的 Add to Slack,或前往 8200.dev → Connectors → Slack → Connect。

我们扫描的内容

  • Channel and file sharing metadata (public/external exposure — never message contents)
  • Installed apps / bots / integrations and their granted token scopes
  • Members, bots, and guests — including 2FA-registration status (never passwords)
  • Workspace configuration: 2FA enforcement, app-install approval, public file sharing, discovery

只读监控——除非您开启自动修复并单独授予写入权限,否则您的 Slack 数据中的任何内容都不会发生变更。

安全发现

每次 Slack 扫描会运行 25 条检测规则。每条发现都附带通俗易懂的说明、支撑证据以及修复步骤。

  • CRITICALPublic exposure

    Public link with edit/owner access

  • CRITICALExternal access

    External principal holds ownership

  • HIGHPublic exposure

    Public link share (link-only)

  • HIGHPublic exposure

    Public + web-discoverable share

  • HIGHExternal access

    External access to sensitive data

  • HIGHExternal access

    External collaborator with edit access

  • HIGHOver permission

    Sensitive resource editable org-wide

  • HIGHOver permission

    Broad group access to sensitive data

  • HIGHAI agent

    Service account with broad write access

  • HIGHAI agent

    AI agent with access to sensitive data

  • HIGHAI agent

    AI agent with edit/owner access

  • HIGHExternal access

    Access granted to a look-alike (typosquat) domain

  • HIGHIdentity

    Two-factor authentication is not enforced for all members

    When 2FA is not required workspace-wide, members can sign in with a password alone, and a single phished or reused credential grants an attacker full access to every channel that member can read. Slack exposes each member’s 2FA status (has_2fa); a material share of members without it means the policy is not enforced.

  • HIGHApplications

    Any member can install apps without admin approval

    When app installation is not restricted to admins, any employee can add a third-party app — including an AI assistant, GPT bot, or automation tool — and grant it access to channels and files with one click. This is the primary shadow-AI / over-broad-bot entry vector in Slack. App installs should route through an admin approval workflow.

  • MEDIUMOver permission

    Broad org-wide edit access (aggregate)

  • MEDIUMOver permission

    Resource with multiple owners

  • MEDIUMStale access

    Stale external read access

  • MEDIUMStale access

    Dormant privileged internal account

  • MEDIUMMisconfig

    Direct share breaks folder inheritance

  • MEDIUMApplications

    Apps installed by deactivated members still hold access

    An app installed by a member who has since been deactivated keeps its bot token and granted scopes — it can still read channels and files even though the person who authorized it, and could attest to why it exists, is gone. These orphaned installs are a quiet source of un-owned, un-reviewed access.

  • MEDIUMSharing

    Files are shared with public ("anyone with the link") URLs

    A file with a public link is reachable by anyone who has the URL — no Slack account, no workspace membership, no sign-in. One forwarded link leaks the file outside the org, and public links on files in private or sensitive channels are an especially sharp exposure.

  • MEDIUMSharing

    Channels are shared externally with other organizations (Slack Connect)

    Slack Connect channels are shared with one or more external organizations, so members of those orgs can read — and often post — in the channel. Each external channel is a data-egress path that needs an owner and a periodic review of which outside parties still belong there.

  • MEDIUMMisconfig

    Vendor AI-training data-contribution posture

  • LOWApplications

    More installed apps than the recommended review threshold

    A large installed-app surface is hard to govern: each app holds a token with scopes, and the more there are, the more likely one is over-permissioned, unused, or an unsanctioned automation. Keeping the count reviewed and pruned shrinks the attack surface.

  • LOWDiscovery

    Workspace can be discovered and joined by email domain

    When workspace discovery by email domain is on, anyone with an email at an approved domain can find and request (or auto-join) the workspace. On a large or shared domain this lets unvetted accounts into the org’s channels; new members should join by invitation or admin approval instead.

如何连接 Slack

可直接在本页面添加至 Slack,或在产品内通过 8200.dev → Connectors → Slack → Connect 添加。两种方式都执行相同的直接 OAuth 安装,并具有相同的只读权限。

  1. 第 1 步

    在本页面点击 Add to Slack——直接安装,无需通过 Marketplace。

  2. 第 2 步

    登录 8200.dev,或在几秒钟内免费注册一个账户。

  3. 第 3 步

    在 Slack 自有的授权页面上选择您的工作区并批准只读权限。

  4. 第 4 步

    8200.dev 会自动扫描——结果将在几分钟内呈现。

8200.dev 向 Slack 发送的内容

警报为可选启用,按频道设置,且仅针对您在 设置 → 集成 中选择的事件发送。以下是可以发布到 Slack 的事件:

  • New security findingfinding.new
  • Finding resolvedfinding.resolved
  • Scan completedscan.completed
  • Scan failedscan.failed
  • Connector unhealthyconnector.unhealthy
  • Connector recoveredconnector.recovered
  • Approaching plan limitentitlement.warning

每条警报为一条 Slack 消息:包含事件的标题、严重程度色条、关键字段(严重程度、类别、标题、来源)以及一个可深度链接至相关发现的“打开 8200.dev”按钮。绝不包含文件内容,绝不包含消息内容。

发送到 Slack 频道的警报示例(数值仅供参考)。

8200.dev 使用 AI 分析安全发现。AI 生成的洞察偶尔可能不够精确——所有发现均应由您的安全团队进行审查。

几分钟内接入您的第一个数据源——免费、只读,无需销售沟通。