Slack
Slack
Edition: Enterprise only
The Slack integration scans messages, threads, and files across public and private channels in your Slack workspace for credentials and other sensitive data. To send TruffleHog detections to Slack as notifications, see the SlackSlack notifier notifier instead.
Slack Continuous
Slack Continuous continuously monitors your workspace for secrets.
It reads only the channels and conversations the TruffleHog Enterprise bot belongs to. Invite the bot to any public or private channel you want scanned.
Slack Continuous monitors your workspace for secrets two ways:
- Continuous secret detection: as messages, files, and edits are posted, TruffleHog Enterprise scans them across public/private channels the app has been invited to.
- Historical secret detection (Slack Enterprise Grid Plan only, coming soon): scans existing workspace content, including attachments and archives, so secrets that leaked before you installed the app don't stay hidden.
Configuration
Slack continuous can be configured in TruffleHog Enterprise under Integrations. Self-hosted scanners are not currently available for this mode.
From the Integrations page in TruffleHog:
- Click Add Integration.
- Select Slack as the source.
- Choose Slack Continuous and continue to TruffleHog's authorization handoff with Slack.
- On Slack's authorization page, click Allow to grant TruffleHog access to your workspace.
- Name your new integration.
Capabilities
Feature | Supported |
|---|---|
Continuous monitoring | ✅ |
Scan public channels (including thread replies) | ✅ |
Scan edited messages | ✅ |
Scan canvases and lists | ✅ |
Scan files shared in conversations | ✅ |
Scan private channels (bot must be invited) | ✅ |
Scan direct messages the bot is part of | ✅ |
Scan group DMs the bot is part of | ✅ |
TruffleHog requests read-only bot scopes. It scans content for secrets but never posts, modifies, or deletes anything in your workspace.
Scope | Why TruffleHog requests it |
|---|---|
channels:history | Read messages in public channels the bot is in, so their content can be scanned. |
groups:history | Read messages in private channels the bot has been invited to. |
im:history | Read direct messages the bot is part of. |
mpim:history | Read group direct messages the bot is part of. |
files:read | Retrieve and scan files shared in those conversations. |
channels:read | See public channel names and details, so findings tie back to the right channel. |
groups:read | See private channel names and details for the same reason. |
im:read | See basic details of direct messages the bot is part of. |
mpim:read | See basic details of group direct messages the bot is part of. |
app_mentions:read | Receive events when the app is @mentioned. |
discovery:read | Read existing organization messages and files to perform historical secret scanning of the full workspace. |
discovery:write | Write messages to channels when the bot is mentioned (not currently implemented). |
Legacy Slack Scanner (to be deprecated)
TruffleHog's legacy Slack scanner is no longer supported. Slack is deprecating the APIs it relied on. Configure any new Slack scanning via Slack Continuous.
These configuration details will remain until the legacy slack scanner is end-of-life.
Configuration
The legacy slack scanner be configured in TruffleHog under Integrations, or via a local configuration file (below).
Hosted configuration
Configure this integration from the Integrations page in TruffleHog. The flow installs a Slack app on your behalf with the appropriate scopes and rate limits.
Self-hosted configuration
Self-hosted configuration requires creating a single-workspace Slack app and using its token. Multi-workspace scanning requires a separate app per workspace.
Step 1: Create the Slack app
- Go to the Slack app creation page and click to create a new app.
- Give the app a name and select the workspace you want TruffleHog to scan. Each app is scoped to one workspace; create separate apps for additional workspaces.
- In User Token Scopes, add the following scopes:
- users:read — read the user directory.
- users:read.email — read user email addresses.
- channels:history — read public channel message history.
- channels:read — list public channels.
- groups:history — read private channel message history.
- groups:read — list private channels.
- files:read — read file content for scanning.
- Save the app and install it to your workspace.
- If your account doesn't have permission to install apps, Slack routes the request to your workspace admin. Give them a heads-up before submitting.
- Copy the generated token. You'll use it as the token value in the configuration below.
Step 2: Configure TruffleHog
Omit the channels field to scan all channels the token has access to.
Configuration options
Field | Type | Required | Description |
|---|---|---|---|
endpoint | string | No | The Slack API endpoint. Defaults to Slack Cloud. |
token | string | Yes | The Slack app token with the scopes listed above. |
channels | list | No | Explicit list of channels to scan. Omit to scan all accessible channels. |
ignoreList | list | No | Channels to skip during scanning. |
Capabilities
Feature | Supported |
|---|---|
Scan public channels | ✅ |
Scan private channels (authorizing user must have access) | Partial |
Scan attachments | ✅ |
Scan archive files | ✅ |
Scan base64-encoded data | ✅ |
Scan binaries | ✅ |
Scan Microsoft Office files | ✅ |
Include / exclude filters | ✅ |
Auto-resume | ✅ |