Skip to content

Slack Connector

Use Slack to deliver alerting, analysis, and discovery notifications to selected channels.

  1. In the app, open Connectors > Slack.
  2. Add the Slack bot token (starts with xoxb-) and optionally a signing secret.
  3. Click Save connection.
  4. Add one or more channels using their channel ID (and an optional label).
  5. Configure event filters for each channel and enable delivery.

Slack notifications are sent for these event types:

  • lookup_result.alerts - Alerts that match the configured filters.
  • lookup_result.analysis - Analysis updates that exceed the phishing score threshold.
  • lookup_result.domain_discovery - Newly discovered domains within the Levenshtein distance threshold.

Each channel has its own filters:

  • Alerts
    • Minimum severity: critical, high, medium, low, informational.
    • Status filter: stable, experimental, deprecated, unsupported.
  • Analysis
    • Phishing score threshold (0.0 - 1.0).
    • Optional “only on change” toggle to skip duplicate results.
  • Domain discovery
    • Levenshtein distance threshold (1 - 12).

Rule alerts are grouped into one message per domain analysis. The message lists each matched rule with its severity and status, followed by a collapsed matched events table with the Domain, Email and Canary records those rules matched. Each row shows the indicator (permutation, sender domain or observed hostname), a short detail, when the record was observed, and the highest severity among the rules that matched it.

The table shows up to 50 records. Alerts record up to 10 matched events per rule and source; the full alert is available under View alerts.

Use the Test action in the channel list to send a confirmation message to a Slack channel to verify the bot token and channel configuration.