Slack Watchman

Ahmed Musaad
Ahmed Musaad
Slack Watchman
Slack Watchman is a handy "application that uses the Slack API to look for potentially sensitive data exposed in your Slack workspaces."

The tool offers a solid starting point for those concerned about the prevalence of sensitive information within their Slack workspace, but can't afford one of the commercial solutions or the price tag of the enterprise plan that's required to use of Slack's DLP APIs. It can also provide great insights into how one can use Slack APIs to build similar useful tools.

GitHub - PaperMtn/slack-watchman: Monitoring your Slack workspaces for sensitive information
Monitoring your Slack workspaces for sensitive information - GitHub - PaperMtn/slack-watchman: Monitoring your Slack workspaces for sensitive information

The tool is a command line one and is simple to configure and run. It looks for all kinds of sensitive information (e.g. API tokens, passwords, passport numbers, IBAN and much more) while requiring a reasonable set of permissions on your workspace.

While I won't write a detailed hands-on guide on how to configure and use this tool, here is the general outline of what you need to do:

  • Install the tool using pip.
  • Create a new Slack app and add the required scopes to it. Note down the app token value (starts with xoxp).
  • Create your configuration file (.conf) for Slack Watchman and make sure to configure it to your liking/needs.
  • Run the tool and consume its output however you want.
If you get stuck at any point, the GitHub repo has excellent documentation, so make sure to check it out.


Great! Next, complete checkout for full access to Ahmed Musaad
Welcome back! You've successfully signed in
You've successfully subscribed to Ahmed Musaad
Success! Your account is fully activated, you now have access to all content
Success! Your billing info has been updated
Your billing was not updated