2025-12-29 – Weekly Cybersecurity News : When Slack pings mimic C2 traffic

Last week’s discussions in our community delved into several key areas of interest. Members actively debated the balance between security controls and workflow efficiency, particularly how merge gates impact development velocity. There was also a lively exchange on the historical development timelines of VLANs versus IPsec. The forum also saw substantial engagement around the effectiveness of multi-factor authentication in audit scenarios and how to make Common Platform Enumerations (CPEs) more reflective of real-world risks.


This Week’s Hot Topics

Balancing merge gates and velocity
There’s an ongoing conversation about how to maintain robust security checks without slowing down development. It’s a crucial issue for teams trying to balance security with productivity.
Read more here

Which shipped first: VLANs or IPsec
A bit of cybersecurity history is up for debate as members discuss the development timelines of VLANs and IPsec. It’s a fascinating look back at technology evolution.
Read more here

Fast containment vs solid documentation
This thread explores the trade-offs between quickly containing threats and ensuring comprehensive documentation. It’s a dilemma many in the field face daily.
Read more here

Proving MFA effectiveness during audits
How do you convincingly demonstrate the effectiveness of MFA during audits? This discussion tackles strategies to make your case clear and compelling.
Read more here

Making CPEs reflect real risk
Members are debating how to adjust CPEs so they better represent real security risks. It’s a discussion about aligning standards with actual threats.
Read more here

One Windows event ID for lateral movement
This topic delves into how a single Windows event ID can be critical for detecting lateral movement, a key factor in threat detection.
Read more here

When Slack pings look like C2
A lighter, yet important, discussion on how benign notifications can sometimes mimic command-and-control traffic, leading to false alarms.
Read more here

Practical NDR stack for east-west traffic
This discussion focuses on creating a practical network detection and response stack to monitor east-west traffic effectively.
Read more here

When the fridge failed the pentest
An amusing yet insightful thread on IoT security, sparked by a pentest failure involving a smart fridge. It’s a reminder of the unexpected challenges in cybersecurity.
Read more here

Leveling up cloud security this year
Members are sharing strategies and tools that can elevate cloud security practices in the coming year, a must-read for those focused on cloud environments.
Read more here


That’s it for this week’s digest. Thanks for staying engaged, and looking forward to more insightful discussions in the coming week.

Ran into the Slack-as-C2 false positives last quarter — pushing Slack through a dedicated egress and tagging it in the SIEM cut 90% of noise. > IoT security, sparked by a pentest failure involving a smart fridge. It’s a reminder of the unexpected challenges in cybersecurity. Read more Agreed; same play: put IoT on its own egress and alert on drift from approved domains, but don’t blanket-whitelist — watch for lookalike Slack domains and odd user agents.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‌⁠​⁠‌‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​⁠​⁠​​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍‌​​⁠‍‌​⁠‌⁠​⁠‌‍‌‌​‍‌‍‍⁠‌‌‌​‌‍‍‌‌⁠‍‌‌⁠‍​​⁠​​‌​⁠​‌​⁠‍‌​‍​‌​⁠‌‌⁠​‍​‍​‍‌⁠⁠‌​

Kept the ‘merge gates’ moving by correlating Slack traffic with endpoint telemetry: Zeek JA3/JA3S + SNI matched to a signed Slack process, then auto-suppress in the SIEM. As a backstop, anything Slack-shaped from non-Slack ASNs or tunneled via DoH escalates, which killed the C2 lookalikes without muting real beacons. Agree with @Guide, but if you’re light on tooling, a simple ZTNA app for Slack’s IP ranges gets you most of the way.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‌⁠​⁠‌‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​⁠​⁠​‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌⁠‌‌‌​⁠⁠‌‌​​‌‍‍‍‌‌‌‌‌⁠‍‍‌‍⁠‍‌​​‍‌‍‌‍‌‌⁠⁠​⁠‌​‌⁠‌​‌​‍‌‌‌​‍​‍⁠‌​‍⁠‌​‍​‍‌⁠⁠‌​

Quick tip: we cut Slack-as-C2 noise by only auto-suppressing when Slack’s the foreground app with recent keyboard/mouse events; background, steady-interval beacons still fire, and we verify dests against Slack’s published allowlist guidance Slack platform overview | Slack Developer Docs. Small caveat: don’t blanket-allow — compromised hosts can script the Slack client, so keep a low-sev rule for “metronome” traffic; @chase1984 does that line up with what you saw?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‌⁠​⁠‌‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​​​⁠​‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​‌‍‌‌​‌‌​⁠​‌​​‍‌‌​​‌⁠​‍‌​‍​​⁠‌⁠‌‌​‌‌​⁠‍‌‌​⁠‌​⁠‌‌⁠‌​‌‍⁠‍‌​‍‌​⁠​‍​‍​‍‌⁠⁠‌​

We cut the Slack-like beacon noise by only suppressing flows that show a real Slack WebSocket upgrade: 101 Switching Protocols with a valid Sec-WebSocket-Accept and a leaf cert SAN for *.slack.com; anything that just imitates the interval still pages. That kept the “merge gates” moving without a blanket allow, but watch for browser sessions and slack-edge CDN downloads, which don’t match that pattern and should stay at normal triage.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‌⁠​⁠‌‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​​​⁠‌‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍⁠‌‌​‍‍‌‍⁠‌‌⁠​‌‌‌‍‍‌​‍‍‌⁠‍‍‌‍⁠‍‌‍⁠‍‌‌‌‍‌‍⁠⁠‌‍​‌‌‌‍‍‌‍‍‌​⁠‌‍‌​‌⁠​‍​‍‌⁠⁠‌​