Slack notifications
Account Defender can automatically send you Slack notifications when it detect incidents matching your existing Policy Rules. You can learn how to configure Slack notifications in this article.
Prerequisites
You need a configured Slack integration. See our help article, Slack Integration, for more information.
Set up Slack notifications
To set up notifications, you need to:
Create a Slack Action
Once you have integrated with Slack, you must contact our team with the Slack channel you want to send the notifications to.
- Add your custom Slack app into a channel in your Slack Workspace. This is the channel that HUMAN will send notifications to.
- Contact HUMAN via your Technical Account Manager, Customer Success representative, or email us with the Slack channel's name.
Our team will set up a Slack Action for you for the specified channel. Once it's created, it will be available to be used in your Account Defender Policy Rules.
Next, be sure to add your Action to a Policy Rule so it triggers automatically.
Add a Slack Action to a Policy Rule
Once you have a Slack Action, we recommend adding it to a Policy Rule so you can automate when a request is sent to your organization. Slack messages can be sent with different fields depending on the attack type:
Field name | Description | Attack type availability |
---|---|---|
AppID | The Application ID the attack was detected on | Network, Single |
Attack Type | The type of attack (either account takeover or fake account) | Network, Single |
Matched rule name | The name of the rule that detected the attack | Network, Single |
Score | The severity score assigned to the attack from 0-100 | Network, Single |
Account IDs | The ID of the users in the network attack, or the ID of the user in a single attack | Network, Single |
Network ID | The unique ID for the network | Network |
To add the Action to a Policy Rule:
- Navigate to Account Defender > Policies > Policy Rules.
- Select Create new rule or select an existing rule to edit it.
- Select Actions and navigate to Alerts & Notifications, which should display your Slack Action.
- In the Then section, drag and drop the Slack Action that should be triggered when the If condition is met.
- Select Save.
Your Policy Rule has been updated with your Slack Action. Now, whenever your rule is triggered, HUMAN will send a Slack message to the channel you specified so you can be notified immediately.
Updated 12 days ago