elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[New Rule] A user previewed multiple Slack rooms without joining in a short period #4136

Open brokensound77 opened 5 days ago

brokensound77 commented 5 days ago

Description

A user previewed multiple Slack rooms without joining in a short period, which could be indicative of performing recon or attempting to locate sensitive information.

Similar to internal: 2243f3ae-62e0-4c36-acc4-7d25cfb07b66

Target Ruleset

other

Target Rule Type

Threshold

Tested ECS Version

No response

Query

This is dependent on the rule_id generated from #4135

user.email:* and kibana.alert.rule.rule_id:"rule-id-of-4135-bbr-rule" 

New fields required in ECS/data sources for this rule?

No response

Related issues or PRs

dependent on #4135

References

https://api.slack.com/admins/audit-logs-call

Redacted Example Data

No response