And suricata lit up at 09:13 with “suspicious beaconing,” and I spent ten minutes carving PCAPs before realizing it was Slack doing its cheerful keepalives through a noisy proxy. Anyone else have benign heartbeat traffic trigger a full threat hunt, or am I the only one measuring jitter like it’s an IOC?
But same pain here — adding a Suricata threshold/suppress rule keyed on Slack SNIs/JA3 so “suspicious beaconing” triggers only after, say, 20 flows in 120s cut the hunts. If the proxy’s chatty, tag its CIDR and require a minimum unique dest count before alerting; Slack is sticky, real C2 usually isn’t: 8.44. Thresholding Keywords — Suricata 9.0.0-dev documentation. Slack’s heartbeat has better uptime than my coffee machine.