AiStrike Documentation

Slack

1. Introduction

This document provides step-by-step instructions for integrating Slack with AiStrike, enabling automated and manual alert notifications, as well as direct incident response actions from Slack.◼︎

2. Prerequisites

  • AiStrike account credentials (email and password provided by AiStrike).

  • Admin permissions for Slack workspace (to approve integrations and manage channels).

  • Existing Slack channel (or ability to create one if needed).

3. Integration Steps

Step 1: Authenticate into AiStrike

  1. Log in to the AiStrike application using your email and password.

  2. Navigate to Dashboard > Integrations from the left side panel.

Step 2: Connect Slack

  • Locate the Slack Connector in the integration list.

  • Click on Connect to Slack.

  • Approve the integration in the Slack authorization window.

  • Upon successful authentication, you will be redirected back to AiStrike.

Step 3: Configure Slack Notifications

  1. Select a Public Slack channel from the dropdown menu.

    • You can either use an existing channel or create a new one in Slack before this step.

  2. To enable drop down of Private, please make sure that @AiStrike is part of the Private channel:

    • Open Slack Application and navigate to the Private channel in which you want notification to be sent.

    • Type @AiStrike and hit enter, this will ask to Add them, Click on "Add Them".

    • Click Reload icon next to Private channel, you will be able to see the channel name.

  3. Click Save to finalize the integration.

4. Using Slack Integration in AiStrike

Remediation Alerts

  • After integration, the Slack connector symbol will be displayed in the Remediation tab of Alerts.

Alert Workflow Configuration

  • Alerts can be sent to Slack via two methods:

    1. Automated Workflow: Messages are sent to Slack automatically whenever a specific alert type is triggered.

    2. Manual Selection: Users can manually send alerts to Slack on demand by selecting the appropriate option.

5. Alert Notifications in Slack

  • Alerts sent to Slack contain key details, including:

    • Alert type and severity.

    • Affected entities and recommended actions.

    • Incident response options.

  • Users can take direct response actions from Slack, such as:

    • Creating tickets for further investigation.

    • Running malware scans.

    • Blocking suspicious IPs.

6. Testing Slack Connectivity and Slack Notifications

  • Navigate to any Composite alerts.

  • Navigate to the Remediations tab.

  • Click on Slack Icon.

  • Notification should be sent to the added channel name in Slack connector configuration.