Skip to content

Slack Watchman for Enterprise Grid 1.0.1

Compare
Choose a tag to compare
@PaperMtn PaperMtn released this 30 Dec 16:46
· 46 commits to main since this release

Slack Watchman for Enterprise Grid - 1.0.1

Slack Watchman for Enterprise Grid uses the Slack Enterprise Grid DLP API to look for potentially sensitive data exposed in your Slack Enterprise.

Note: Slack Watchman for Enterprise Grid is designed for Enterprise Grid subscribers of Slack only. If you use Slack without an Enterprise subscription, you can use the standard version of Slack Watchman

Features

Slack Watchman for Enterprise Grid looks for:

  • API Keys, Tokens & Service Accounts
    • AWS, Azure, GCP, Google API, Slack (keys & webhooks), Twitter, Facebook, GitHub
    • Generic Private keys
    • Access Tokens, Bearer Tokens, Client Secrets, Private Tokens
  • Files
    • Certificate files
    • Potentially interesting/malicious/sensitive files (.docm, .xlsm, .zip etc.)
    • Executable files
    • Keychain files
    • Config files for popular services (Terraform, Jenkins, OpenVPN and more)
  • Personal Data
    • Leaked passwords
    • Passport numbers, Dates of birth, Social security numbers, National insurance numbers, Drivers licence numbers (UK), Individual Taxpayer Identification Number
    • CVs, salary information
  • Financial data
    • PayPal Braintree tokens, Bank card details, IBAN numbers, CUSIP numbers
    • Budget files

It looks for this exposed data across all workspaces in the Enterprise, in the following locations:

  • Public channels
  • Private channels
  • Draft messages
  • Slack connect channels
  • Direct messages
  • Multi-person direct messages