detections
- ID: DT155
- Created: 03rd May 2026
- Updated: 03rd May 2026
- Contributor: The ITM Team
Slack Data Export Conversation Analysis
Analyze authorized Slack data exports to review message content, conversation history, participants, timestamps, file links, and related metadata from Slack conversations. Slack data exports provide investigators with a structured record of communications across supported conversation types, which may include public channels, private channels, and direct messages depending on the organization’s Slack plan, export permissions, retention settings, and approved export scope. Slack states that Business+ and Enterprise export options can include messages and file links from public channels, private channels, and direct messages, subject to the applicable export process.
Investigators can use Slack export files to identify conversations involving a subject, reconstruct communication timelines, assess message context, and correlate communications between parties. Slack explains that exports include reference files such as users.json, channels.json, groups.json, and dms.json; investigators can use these files to identify user IDs, locate conversations containing relevant parties, and then review the corresponding conversation folder containing date-based JSON message files.
Relevant artifacts include the original Slack export ZIP file, users.json, channels.json, groups.json, dms.json, conversation folders, date-based JSON message files, user IDs, conversation IDs, message timestamps, thread timestamps, message text, file links, and edit or deletion indicators where retained in the export. Investigators should preserve the original export, collection scope, export date range, workspace identifier, relevant user IDs, conversation IDs, and review notes to maintain evidential integrity.
Message availability should be validated before investigative conclusions are drawn. Slack retention settings can apply to public channels, private channels, and direct messages, meaning exported content may be limited by the organization’s configured retention policy and the scope of data available at the time of export.
Sections
| ID | Name | Description |
|---|---|---|
| PR050 | Trusted Relationship Cultivation | A subject deliberately develops a relationship of trust with a colleague, administrator, service provider, customer, or control owner to obtain future assistance, information, approval, or reduced scrutiny.
The conduct may involve repeatedly offering help, volunteering for tasks, creating dependency, demonstrating apparent reliability, or establishing informal communication outside approved processes. The relationship is later used to secure exceptional access, accelerate a request, obtain confidential information, bypass verification, or discourage challenge.
This would not classify ordinary professional relationship-building. Investigative relevance arises where the relationship is developed or exploited to enable a subsequent infringement. |
| IF044 | Abuse of Decision-Making Authority | A subject deliberately uses a decision-making authority granted through their organizational role to approve, deny, waive, prioritize, suppress, or otherwise determine an outcome for an unauthorized purpose.
The subject may be technically and procedurally entitled to make the decision. The infringement arises because the authority is exercised contrary to the organization’s interests, applicable policy, delegated limits, or the legitimate purpose for which the authority was granted.
This behavior may be difficult to identify through conventional access-control monitoring because the subject acts through authorized workflows and assigned permissions. Investigation requires examination of the decision, its stated justification, the subject’s relationship to affected parties, applicable policy requirements, and comparable decisions made under similar circumstances.
This is narrower than general “authority abuse.” It focuses on the improper exercise of an entrusted decision right. |
| AF030.001 | Deletion of Corporate Communication Messages | The subject deletes messages from organization-managed communication platforms such as enterprise collaboration tools, internal messaging systems, or other corporate communication environments.
These platforms commonly contain operational discussions, requests for information, coordination between staff, or exchanges relating to sensitive work activities. Deleting messages from these systems may remove evidence of policy violations, improper instructions, or coordination with other individuals.
In many enterprise platforms, message deletion events generate administrative audit artifacts. While the message content may no longer be visible to users, deletion activity can often still be identified through platform audit logs, retention systems, or administrative investigation tools. |
| PR022.003 | Outbound Social Engineering via SMS or Messaging | A subject uses SMS, mobile messaging, or collaboration messaging platforms to deceive, manipulate, or persuade another person into disclosing information, clicking a link, approving access, moving a conversation to another channel, or performing an action that may support a later infringement. This may involve corporate messaging tools, personal messaging applications, mobile numbers, or externally hosted communication services.
This behavior may exploit the informal, immediate, and trusted nature of messaging channels. The subject may rely on urgency, familiarity, limited message context, or out-of-band communication to reduce scrutiny and influence the recipient’s response. The intended outcome may include credential capture, information disclosure, access approval, link interaction, process bypass, or coordination of activity outside formal organizational workflows. |
| IF043.003 | Equipment or Facility Diversion | A subject redirects organizational equipment, vehicles, facilities, laboratories, production capability, or other physical assets toward an unauthorized use. Harm may include reduced availability, damage, operating cost, or disruption to legitimate activity. |
| IF044.001 | Unauthorized Approval | A subject uses delegated authority to approve a request, transaction, entitlement, exception, appointment, payment, access grant, or other organizational action without a legitimate basis.
Examples include:
The defining evidence is an affirmative decision made through authority legitimately assigned to the subject. |
| IF044.002 | Improper Denial | A subject uses organizational authority to deny another person a service, benefit, request, opportunity, access right, payment, review, or other outcome without a legitimate organizational basis.
Examples include:
|
| IF044.003 | Improper Preferential Treatment | A subject uses decision-making authority to provide an unauthorized advantage to a person, organization, account, supplier, applicant, or other beneficiary.
Examples include:
|
| IF044.005 | Unauthorized Waiver or Control Exception | A subject improperly waives, bypasses, suspends, or grants an exception to a mandatory organizational control using authority available through their role.
Examples include:
|
| IF044.006 | Unauthorized Prioritization or Deprioritization | A subject uses decision-making authority to improperly accelerate, delay, elevate, or deprioritize a request, case, transaction, task, customer, or other item within an organizational process.
Examples include:
|
| AF030.003 | Use of Disappearing or Self-Deleting Messages | A subject enables or uses a communication feature that automatically deletes messages after they are read, after a defined period, or when a conversation is closed, with the intention of reducing the communication evidence available to investigators.
The subject may use disappearing-message functionality within an approved corporate platform or through a non-corporate messaging application. Automatic deletion may be configured for an individual conversation, group, channel, workspace, or account. The subject may also change an existing conversation from persistent retention to temporary retention before exchanging information connected to an infringement.
This behavior differs from the manual deletion of corporate or non-corporate messages because the removal mechanism is established before or during the communication. Messages may disappear without a separate deletion action being performed after each message is sent.
Investigators should examine when the disappearing-message setting was enabled, who enabled it, the configured retention period, which participants were involved, and whether the setting was changed shortly before sensitive or suspicious communications occurred. The ordinary availability of an ephemeral messaging feature does not establish anti-forensic intent; classification should require evidence that the feature was deliberately used to reduce investigative visibility. |
| AF030.004 | Bulk Deletion of Message History | A subject deletes a substantial volume of messages, conversations, threads, channels, or communication history to remove or materially reduce the records available for investigation.
Bulk deletion may involve selecting and deleting multiple messages, repeatedly deleting individual messages within a short period, clearing an entire conversation, removing channel history, deleting archived communications, or using scripts, administrative tools, application programming interfaces, or automation to remove content at scale.
The behavior may occur after the subject becomes aware of an investigation, disciplinary process, access review, audit, legal dispute, or anticipated offboarding. It may also occur immediately before the subject conducts another infringement where prior communications could reveal planning, coordination, relationships, or intent.
The significance of bulk deletion should be assessed against the subject’s normal messaging activity, the amount of content removed, the time period affected, the platforms involved, and whether the deleted communications related to known subjects, external parties, sensitive projects, or active investigations.
Investigators should identify deletion event volume, timestamps, conversation identifiers, affected participants, client or application source, administrative actions, and any corresponding data preserved through retention or legal-hold systems. |
| AF030.005 | Administrative Deletion of Communication Messages | A subject uses administrative, moderation, ownership, compliance, or delegated platform privileges to delete messages created by another subject or to remove communication records from a shared organizational environment.
The subject may delete individual messages, conversation threads, channel content, direct-message history, group discussions, or entire communication spaces. Because the subject acts through an elevated or delegated role, the deletion may affect evidence belonging to several participants and may remove communications that the original author could not delete themselves.
This behavior may be used to conceal improper instructions, remove evidence of collusion, suppress complaints, protect another subject, or interfere with an active investigation. The administrative action may appear legitimate where the subject normally manages inappropriate content, retention, moderation, or workspace administration.
Investigators should assess whether the deletion was supported by an approved moderation, legal, records-management, or operational requirement. Relevant evidence includes the administrative identity used, the original message author, affected participants, deletion reason, approval records, platform audit logs, retention configuration, and the relationship between the deleting subject and those whose messages were removed.
The use of administrative privileges alone does not establish anti-forensic conduct. Classification should require evidence that the deletion was unauthorized or intended to remove evidence relevant to an insider event. |
| AF030.006 | Deletion of Communication Containers | A subject deletes a channel, group, workspace, conversation, mailbox folder, discussion board, or other communication container to remove the messages and associated context held within it.
Deleting a communication container may remove or obscure a larger body of evidence than deleting individual messages. The affected records may include message content, participant lists, timestamps, thread relationships, attachments, reactions, membership changes, and links to other organizational material.
The subject may delete the container after communications associated with an infringement have concluded, after participants have left the group, or after the subject becomes aware that the communication environment may be reviewed. They may also rename, archive, or move the container before deletion to make it more difficult to identify.
Investigators should establish who created, owned, administered, archived, and deleted the container; when the deletion occurred; which participants and messages were affected; and whether the activity followed an alert, complaint, investigation, or other relevant event. Platform audit records, retention systems, backups, legal holds, exports, and participant devices may allow the deleted content or surrounding metadata to be reconstructed. |