1. Introduction
This document provides step-by-step instructions for integrating Slack with AiStrike, enabling automated and manual alert notifications, as well as direct incident response actions from Slack.◼︎
2. Prerequisites
-
AiStrike account credentials (email and password provided by AiStrike).
-
Admin permissions for Slack workspace (to approve integrations and manage channels).
-
Existing Slack channel (or ability to create one if needed).
3. Integration Steps
Step 1: Authenticate into AiStrike
-
Log in to the AiStrike application using your email and password.
-
Navigate to Dashboard > Integrations from the left side panel.
Step 2: Connect Slack
-
Locate the Slack Connector in the integration list.
-
Click on Connect to Slack.
-
Approve the integration in the Slack authorization window.
-
Upon successful authentication, you will be redirected back to AiStrike.
Step 3: Configure Slack Notifications
-
Select a Public Slack channel from the dropdown menu.
-
You can either use an existing channel or create a new one in Slack before this step.
-
-
To enable drop down of Private, please make sure that
@AiStrikeis part of the Private channel:-
Open Slack Application and navigate to the Private channel in which you want notification to be sent.
-
Type
@AiStrikeand hit enter, this will ask to Add them, Click on "Add Them". -
Click Reload icon next to Private channel, you will be able to see the channel name.
-
-
Click Save to finalize the integration.
4. Using Slack Integration in AiStrike
Remediation Alerts
-
After integration, the Slack connector symbol will be displayed in the Remediation tab of Alerts.
Alert Workflow Configuration
-
Alerts can be sent to Slack via two methods:
-
Automated Workflow: Messages are sent to Slack automatically whenever a specific alert type is triggered.
-
Manual Selection: Users can manually send alerts to Slack on demand by selecting the appropriate option.
-
5. Alert Notifications in Slack
-
Alerts sent to Slack contain key details, including:
-
Alert type and severity.
-
Affected entities and recommended actions.
-
Incident response options.
-
-
Users can take direct response actions from Slack, such as:
-
Creating tickets for further investigation.
-
Running malware scans.
-
Blocking suspicious IPs.
-
6. Testing Slack Connectivity and Slack Notifications
-
Navigate to any Composite alerts.
-
Navigate to the Remediations tab.
-
Click on Slack Icon.
-
Notification should be sent to the added channel name in Slack connector configuration.