{"id":55119,"date":"2025-05-20T05:00:00","date_gmt":"2025-05-20T13:00:00","guid":{"rendered":"https:\/\/www.sumologic.com\/blog\/sumo-logic-cloud-siem%ec%9d%84-%ec%9d%b4%ec%9a%a9%ed%95%9c-slack-%ed%99%98%ea%b2%bd%ec%9d%98-%ec%95%88%ec%a0%84%ed%95%9c-%eb%b3%b4%ed%98%b8"},"modified":"2026-02-25T04:27:48","modified_gmt":"2026-02-25T12:27:48","slug":"monitor-slack-audit-logs-cloud-siem","status":"publish","type":"blog","link":"https:\/\/www.sumologic.com\/ko\/blog\/monitor-slack-audit-logs-cloud-siem","title":{"rendered":"Sumo Logic Cloud SIEM\uc744 \uc774\uc6a9\ud55c Slack \ud658\uacbd\uc758 \uc548\uc804\ud55c \ubcf4\ud638"},"content":{"rendered":"\n<section class=\"e-stn e-stn-0d652506f82b000a392973813b918ee25d5b4211 e-stn--glossary-inner-content e-stn--table-of-content\"><div class=\"container\">\n<div class=\"wp-block-b3rg-row e-row row\">\n<div class=\"wp-block-b3rg-column e-col e-col-1f7b3997080fc292474d26ff00c905d99d3520fa e-col--content-wrapper  col-sm-12 col-lg-12 col-xl-12\">\n<div class=\"e-div e-div-a1b32f66e1749758df41d5aea14f647cd10e362c e-div--card-btn-link\"><div class=\"e-img \">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"293\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/Header-blog-ThreatLabs_Slack_700x200_V2-1024x293.webp\" alt=\"Sumo Logic: Slack &#xD658;&#xACBD; &#xBCF4;&#xC548; &#xAC15;&#xD654;\" class=\"wp-image-25562\" title=\"\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/Header-blog-ThreatLabs_Slack_700x200_V2-1024x293.webp 1024w, https:\/\/www.sumologic.com\/wp-content\/uploads\/Header-blog-ThreatLabs_Slack_700x200_V2-300x86.webp 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/Header-blog-ThreatLabs_Slack_700x200_V2-768x219.webp 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/Header-blog-ThreatLabs_Slack_700x200_V2-575x164.webp 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/Header-blog-ThreatLabs_Slack_700x200_V2.webp 1400w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<p>Slack\uc740 \uc774\uc81c \ub9ce\uc740 \uc870\uc9c1\uc5d0\uc11c \ud575\uc2ec\uc801\uc778 \ud611\uc5c5 \ud50c\ub7ab\ud3fc\uc73c\ub85c \uc790\ub9ac \uc7a1\uc558\uc2b5\ub2c8\ub2e4. \uc870\uc9c1 \ub0b4\uc678\uc758 \ucee4\ubba4\ub2c8\ucf00\uc774\uc158\ubd80\ud130 \ud504\ub85c\uc81d\ud2b8 \uc6cc\ud06c\ud50c\ub85c\uae4c\uc9c0, \ub2e4\uc591\ud55c \uc5c5\ubb34\uac00 Slack\uc744 \uc911\uc2ec\uc73c\ub85c \uc6b4\uc601\ub418\uace0 \uc788\uc2b5\ub2c8\ub2e4. \ud558\uc9c0\ub9cc \uc0ac\uc6a9\uc774 \ub298\uc5b4\ub0a0\uc218\ub85d \uc704\ud5d8\ub3c4 \ud568\uaed8 \uc99d\uac00\ud569\ub2c8\ub2e4. Slack\uc5d0\ub294 \uc9c0\uc801 \uc7ac\uc0b0, \uc778\uc99d \uc815\ubcf4, \uadf8\ub9ac\uace0 \uacf5\uaca9\uc790\uac00 \uc0ac\uc804 \uc815\ucc30\uc5d0 \ud65c\uc6a9\ud560 \uc218 \uc788\ub294 \ub2e4\uc591\ud55c \uc815\ubcf4\uac00 \ud3ec\ud568\ub418\uc5b4 \uc788\uc5b4, \uacf5\uaca9\uc790\ub4e4\uc5d0\uac8c \ub9e4\uc6b0 \ub9e4\ub825\uc801\uc778 \ud45c\uc801\uc774 \ub418\uace0 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.sumologic.com\/ko\/solutions\/cloud-siem\" target=\"_blank\" data-type=\"link\" data-id=\"https:\/\/www.sumologic.com\/solutions\/cloud-siem\" rel=\"noreferrer noopener\">Sumo Logic Cloud SIEM<\/a>\uc740 \uc774\uc81c Slack\uc758 <a href=\"https:\/\/www.sumologic.com\/glossary\/audit-log\">\uac10\uc0ac \ub85c\uadf8(audit log)<\/a>\ub97c \ubaa8\ub2c8\ud130\ub9c1\ud558\uc5ec \uc758\uc2ec\uc2a4\ub7ec\uc6b4 \ud65c\ub3d9\uc744 \ud0d0\uc9c0\ud558\uace0, \ub0b4\ubd80\uc790 \ubc0f \uc678\ubd80 \uc704\ud611\uc73c\ub85c\ubd80\ud130 Slack \uc0ac\uc6a9 \ud658\uacbd\uc744 \ubcf4\ud638\ud569\ub2c8\ub2e4. \uc774\ub97c \ud1b5\ud574 \uae30\uc5c5\uc758 \ub370\uc774\ud130\uc640 \uc2dc\uc2a4\ud15c\uc744 \uc548\uc804\ud558\uac8c \uc720\uc9c0\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-a-10-stolen-slack-cookie-led-to-a-major-breach\">\ub3c4\ub09c\ub41c 10\ub2ec\ub7ec\uc9dc\ub9ac Slack \ucfe0\ud0a4\ub85c \uc778\ud55c \ub300\uaddc\ubaa8 \uce68\ud574 \uc0ac\uace0<\/h2>\n\n\n\n<p><a href=\"https:\/\/www.ea.com\/news\/ea-statement-on-june-11-security-incident\" target=\"_blank\" rel=\"noreferrer noopener\">EA(Electronic Arts)\uc758 \ubcf4\uc548 \uce68\ud574 \uc0ac\ub840<\/a>\uac00 \uadf8 \ub300\ud45c\uc801\uc778 \uc608\uc785\ub2c8\ub2e4. \uc774 \uc0ac\uac74\uc5d0\uc11c,\u00a0<a href=\"https:\/\/www.vice.com\/en\/article\/how-ea-games-was-hacked-slack\/\" target=\"_blank\" rel=\"noreferrer noopener\">\uacf5\uaca9\uc790\ub294 10\ub2ec\ub7ec\uc5d0 \ud310\ub9e4\ub41c \ub3c4\ub09c\ub41c Slack \ucfe0\ud0a4\ub97c \uad6c\ub9e4\ud588\uc2b5\ub2c8\ub2e4<\/a>. \uadf8 \uad6c\ub9e4\ub85c \uacf5\uaca9\uc790\ub294 EA \ub0b4\ubd80 Slack \ucc44\ub110\uc5d0 \uc811\uadfc\ud560 \uc218 \uc788\uc5c8\uace0, \uc774\ub97c \uc774\uc6a9\ud574 IT \ud300\uc744 \uc0ac\ud68c\uacf5\ud559\uc801\uc73c\ub85c \uc18d\uc5ec EA\uc758 \ub0b4\ubd80 \ub124\ud2b8\uc6cc\ud06c \uc811\uadfc \ud1a0\ud070\uc744 \ud655\ubcf4\ud588\uc2b5\ub2c8\ub2e4. \uadf8 \uacb0\uacfc, \uacf5\uaca9\uc790\ub294 FIFA 21 \uac8c\uc784\uc758 \uc18c\uc2a4 \ucf54\ub4dc\uc640 \ub3c5\uc810 \uc18c\ud504\ud2b8\uc6e8\uc5b4 \uac1c\ubc1c \ud0a4\ud2b8\ub97c \ud3ec\ud568\ud574 \ucd1d 780GB\uc5d0 \ub2ec\ud558\ub294 \ub370\uc774\ud130\ub97c \ud0c8\ucde8\ud588\uc2b5\ub2c8\ub2e4.\u00a0<\/p>\n\n\n\n<p>EA\ub9cc\uc758 \ubb38\uc81c\uac00 \uc544\ub2c8\uc5c8\uc2b5\ub2c8\ub2e4. <a href=\"https:\/\/www.wsj.com\/business\/media\/internal-disney-communications-leaked-online-after-hack-b57baaeb\" target=\"_blank\" rel=\"noreferrer noopener\">\ub514\uc988\ub2c8(Disney)<\/a>, <a href=\"https:\/\/www.cpomagazine.com\/cyber-security\/rockstar-gta6-leak-came-from-cyber-attack-that-breached-internal-slack-channel\/\" target=\"_blank\" rel=\"noreferrer noopener\">\ub85d\uc2a4\ud0c0(Rockstar)<\/a>, <a href=\"https:\/\/www.cpomagazine.com\/cyber-security\/major-cybersecurity-incident-at-uber-network-breach-began-with-social-engineering-by-teenage-culprit-sensitive-information-stored-in-plaintext\/\" target=\"_blank\" rel=\"noreferrer noopener\">\uc6b0\ubc84(Uber)<\/a>, <a href=\"https:\/\/mashable.com\/article\/slack-key-to-twitter-hack\" target=\"_blank\" rel=\"noreferrer noopener\">\ud2b8\uc704\ud130(Twitter)<\/a> \ub4f1 \uc5ec\ub7ec \uc720\uba85 \uae30\uc5c5\ub4e4\ub3c4 Slack\uc774 \uacf5\uaca9 \uc131\uacf5\uc758 \ud575\uc2ec\uc801\uc778 \uc5ed\ud560\uc744 \ud588\ub358 \uce68\ud574 \uc0ac\uace0\ub97c \uacaa\uc5c8\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<p>Slack\uc774 \uacf5\uaca9\uc790\uc5d0\uac8c \ud45c\uc801\uc73c\ub85c \uc120\ud0dd\ub418\ub294 \uc774\uc720\ub294 \ubd84\uba85\ud569\ub2c8\ub2e4. Slack\uc740 \ucd08\uae30 \uc811\uadfc, \ub0b4\ubd80 \ud0d0\uc0c9, \uc790\uaca9 \uc99d\uba85 \ud0c8\ucde8, \ub370\uc774\ud130 \uc720\ucd9c \ub4f1 \ub2e4\uc591\ud55c \uacf5\uaca9 \uc804\uc220\uc774 \uc2e4\ud589\ub418\uae30\uc5d0 \uc801\ud569\ud55c \ud658\uacbd\uc744 \uc81c\uacf5\ud569\ub2c8\ub2e4. \ub530\ub77c\uc11c Slack\uc740 \uacf5\uaca9\uc790\uac00 \uc774\uc6a9\ud558\ub294 \ud575\uc2ec \uac70\uc810\uc774\uc790, \ub54c\ub85c\ub294 \ucd5c\uc885 \ubaa9\ud45c\ub85c \uc791\uc6a9\ud558\uae30\ub3c4 \ud569\ub2c8\ub2e4.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why-slack-s-audit-logs-are-key-for-better-security\">Slack \uac10\uc0ac \ub85c\uadf8: \ubcf4\uc548 \uac15\ud654\ub97c \uc704\ud55c \ud575\uc2ec \uc694\uc18c<\/h2>\n\n\n\n<p>\uc774\ucc98\ub7fc Slack\uc740 \uacf5\uaca9\uc790\uc5d0\uac8c \ub9e4\ub825\uc801\uc778 \ud45c\uc801\uc774\uae30 \ub54c\ubb38\uc5d0, Slack \ud658\uacbd\uc740 \uc545\uc758\uc801 \ud589\uc704\ub97c \uc9c0\uc18d\uc801\uc73c\ub85c \ubaa8\ub2c8\ud130\ub9c1\ud574\uc57c \ud569\ub2c8\ub2e4.<\/p>\n\n\n\n<p>\uc774 \ubaa8\ub2c8\ud130\ub9c1\uc744 \uc2dc\uc791\ud558\ub294 \ubc29\ubc95 \uc911 \ud558\ub098\ub294 \ubc14\ub85c \ub85c\uadf8(log)\ub97c \ud65c\uc6a9\ud558\ub294 \uac83\uc785\ub2c8\ub2e4.\u00a0<a href=\"https:\/\/help.sumologic.com\/docs\/integrations\/saas-cloud\/slack\/#log-types\" target=\"_blank\" rel=\"noreferrer noopener\">Slack\uc740 \uac10\uc0ac \ub85c\uadf8(audit log), \uc811\uadfc \ub85c\uadf8(access log)<\/a> \ub4f1 \uc5ec\ub7ec \ud615\ud0dc\uc758 \ub85c\uadf8\ub97c \uc81c\uacf5\ud569\ub2c8\ub2e4. \uc774 \ube14\ub85c\uadf8\uc5d0\uc11c\ub294 \uadf8\uc911\uc5d0\uc11c\ub3c4\u00a0<a href=\"https:\/\/api.slack.com\/admins\/audit-logs#what\" target=\"_blank\" rel=\"noreferrer noopener\">\uac10\uc0ac \ub85c\uadf8<\/a>\uc5d0 \ucd08\uc810\uc744 \ub9de\ucd94\uc5b4 \uc0b4\ud3b4\ubcf4\uaca0\uc2b5\ub2c8\ub2e4. Slack\uc5d0\uc11c \uc0dd\uc131\ub418\ub294\u00a0\uac10\uc0ac \ub85c\uadf8\ub294 \u201c\uc9c0\uc18d\uc801\uc778 \uaddc\uc815 \uc900\uc218\ub97c \ubcf4\uc7a5\ud558\uace0, \ubd80\uc801\uc808\ud55c \uc2dc\uc2a4\ud15c \uc811\uadfc\uc73c\ub85c\ubd80\ud130 \ubcf4\ud638\ud558\uba70, \uae30\uc5c5 \ub0b4\uc5d0\uc11c \ubc1c\uc0dd\ud558\ub294 \uc758\uc2ec\uc2a4\ub7ec\uc6b4 \ud65c\ub3d9\uc744 \uac10\uc0ac\ud558\uae30 \uc704\ud55c \uac83\u201d\uc785\ub2c8\ub2e4.<\/p>\n\n\n\n<p>\uc774\ub7ec\ud55c \uac10\uc0ac \ub85c\uadf8\uc640 \uc774\ub97c API\ub97c \ud1b5\ud574 \uc811\uadfc\ud560 \uc218 \uc788\ub294 \uae30\ub2a5\uc740, <a href=\"https:\/\/www.sumologic.com\/ko\/solutions\/cloud-siem\">Sumo Logic\uacfc \uac19\uc740 SIEM \uc194\ub8e8\uc158<\/a>\uc774 \ubcf4\uc548 \ubaa8\ub2c8\ud130\ub9c1 \ubc0f \ud1b5\ud569 \ubd84\uc11d\uc744 \uc218\ud589\ud558\ub294 \ub370 \ud544\uc218\uc801\uc778 \uae30\ubc18\uc774 \ub429\ub2c8\ub2e4.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"use-slack-s-audit-logs-to-perform-threat-detection\">Slack\uc758 \uac10\uc0ac \ub85c\uadf8\ub97c \ud65c\uc6a9\ud55c \uc704\ud611 \ud0d0\uc9c0<\/h3>\n\n\n\n<p><a href=\"https:\/\/slack.engineering\/slack-audit-logs-and-anomalies\/\" target=\"_blank\" rel=\"noreferrer noopener\">Slack \uac10\uc0ac \ub85c\uadf8<\/a>\uc5d0\ub294 \uc774\uc0c1 \uc774\ubca4\ud2b8(Anomaly Event)\ub77c\ub294 \ub9e4\uc6b0 \uc720\uc6a9\ud55c \uae30\ub2a5\uc774 \ud3ec\ud568\ub418\uc5b4 \uc788\uc2b5\ub2c8\ub2e4. \uc774\ub294 Slack\uc774 \ube44\uc815\uc0c1\uc801\uc778 \ud589\uc704\ub098 \ud589\ub3d9 \ud328\ud134\uc744 \uac10\uc9c0\ud560 \ub54c \uc790\ub3d9\uc73c\ub85c \uc0dd\uc131\ub418\ub294 \uc774\ubca4\ud2b8\uc785\ub2c8\ub2e4. \ubaa8\ub4e0 \uc774\uc0c1 \uc774\ubca4\ud2b8\uac00 \uc989\uac01\uc801\uc778 \ub300\uc751\uc744 \uc694\uad6c\ud558\ub294 \uac83\uc740 \uc544\ub2d9\ub2c8\ub2e4. \uc774\uc0c1 \uc774\ubca4\ud2b8\ub9c8\ub2e4 \uc2e0\ub8b0 \uc218\uc900(confidence level)\uc774 \ub2e4\ub974\uae30 \ub54c\ubb38\uc785\ub2c8\ub2e4. \ud558\uc9c0\ub9cc \uc774\uc0c1 \uc774\ubca4\ud2b8\uac00 \ud2b8\ub9ac\uac70\ub418\uba74, \uadf8 \ud65c\ub3d9\uc744 \ubd84\uc11d\ud558\uc5ec \uc870\uce58\uac00 \ud544\uc694\ud55c\uc9c0\ub97c \ud310\ub2e8\ud560 \ud544\uc694\uac00 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<p>Slack\uc740 \uc774\uc0c1 \uc774\ubca4\ud2b8\ub9c8\ub2e4 \uc2e0\ub8b0 \uc218\uc900\uc744 \uba85\uc2dc\uc801\uc73c\ub85c \uc81c\uacf5\ud558\uc9c0\ub294 \uc54a\uc9c0\ub9cc, \uc77c\ubd80 \uc774\ubca4\ud2b8\uc758 \uacbd\uc6b0 \uce68\ud574 \uac00\ub2a5\uc131\uc774 \ub192\uc740(high-confidence) \uc9c0\ud45c\ub85c \uac04\uc8fc\ud55c\ub2e4\uace0 \ubc1d\ud799\ub2c8\ub2e4.\u00a0<\/p>\n\n\n\n<p>Slack\uc758 <a href=\"https:\/\/slack.com\/help\/articles\/37193054707603-Configure-audit-log-anomaly-event-responses-in-Slack\" target=\"_blank\" rel=\"noreferrer noopener\">\uc774\uc0c1 \uc774\ubca4\ud2b8 \ub300\uc751 \uae30\ub2a5<\/a>\uc740 \uc5b4\ub5a4 \uc774\ubca4\ud2b8\uac00 \uace0\uc2e0\ub8b0(high-confidence) \uc774\ubca4\ud2b8\ub85c \ubd84\ub958\ub418\ub294\uc9c0\ub97c \ubcf4\uc5ec\uc90d\ub2c8\ub2e4. \uc774 \uae30\ub2a5\uc740 \ud2b9\uc815 \uc774\uc0c1 \uc774\ubca4\ud2b8\uac00 \ubc1c\uc0dd\ud560 \uacbd\uc6b0 \ud574\ub2f9 \uc0ac\uc6a9\uc790\uc758 \uc138\uc158\uc744 \uc790\ub3d9\uc73c\ub85c \uc885\ub8cc\ud558\ub3c4\ub85d \uc124\uc815\ub418\uc5b4 \uc788\uc2b5\ub2c8\ub2e4. Slack \uc5d4\uc9c0\ub2c8\uc5b4\ub9c1 \ud300\uc740 \uae30\ubcf8\uc801\uc73c\ub85c \u2018Tor \ucd9c\uad6c \ub178\ub4dc(Tor exit node)\uc5d0\uc11c Slack\uc5d0 \uc811\uadfc\u2019\ud558\ub294 \uc774\ubca4\ud2b8\uc640 \u2018\ub370\uc774\ud130 \uc2a4\ud06c\ub808\uc774\ud551(data scraping)\u2019\uc744 \uace0\uc2e0\ub8b0 \uce68\ud574 \uc774\ubca4\ud2b8\ub85c \uac04\uc8fc\ud558\uace0 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<p>Slack\uc758 \uc774\uc0c1 \uc774\ubca4\ud2b8\ub294 SIEM \ud658\uacbd\uc5d0\uc11c \uc218\uc9d1 \ubc0f \ubd84\uc11d\uc774 \uac00\ub2a5\ud558\ub2e4\ub294 \uc810\uc5d0\uc11c \ubcf4\uc548\ud300\uc5d0 \ud2b9\ud788 \uc720\uc6a9\ud569\ub2c8\ub2e4. Sumo Logic Cloud SIEM\uc740 Slack\uc758 \uc774\uc0c1 \uc774\ubca4\ud2b8\ub97c \uc644\ubcbd\ud558\uac8c \uc9c0\uc6d0\ud558\uba70, \uc774\ubca4\ud2b8\ub97c <a href=\"https:\/\/help.sumologic.com\/docs\/cse\/rules\/normalized-threat-rules\/\" target=\"_blank\" rel=\"noreferrer noopener\">\uc704\ud611 \uacbd\uace0(Threat Alert)\ub85c \uc815\uaddc\ud654\ud558\uc5ec<\/a> \u2018Normalized Security Signal\u2019(MATCH-S00402) \uaddc\uce59\uc744 \uc790\ub3d9\uc73c\ub85c \ud2b8\ub9ac\uac70\ud569\ub2c8\ub2e4. \uc774\ub97c \ud1b5\ud574 \uc774\uc0c1 \uc774\ubca4\ud2b8\uac00 \uac01 \uc5d4\ud130\ud2f0\uc758 <a href=\"https:\/\/help.sumologic.com\/docs\/cse\/get-started-with-cloud-siem\/insight-generation-process\/#understanding-entity-activity-scores\" target=\"_blank\" rel=\"noreferrer noopener\">\ud65c\ub3d9 \uc810\uc218(Activity Score)<\/a>\uc5d0 \ubc18\uc601\ub418\uba70, \ubcf4\uc548 \ubd84\uc11d\ud300\uc740 \uc704\ud5d8\ub3c4\uac00 \ub192\uc740 \uc0ac\uc6a9\uc790\ub098 \uc2dc\uc2a4\ud15c\uc744 \uc2e0\uc18d\ud558\uac8c \uc2dd\ubcc4\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"705\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img1-1-1024x705.png 1024w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img1-1-300x206.png 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img1-1-768x528.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img1-1-575x396.png 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img1-1.png 1404w\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img1-1-1024x705.png\" alt=\"blog slack env img1 1\" title=\"\"><\/p>\n\n\n\n<p><em>Sumo Logic Cloud SIEM \uc2e0\ud638\ub85c \uc804\ub2ec\ub418\ub294 Slack\uc758 \uc774\uc0c1 \uc774\ubca4\ud2b8<\/em><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"748\" height=\"1024\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img2-1-748x1024.png 748w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img2-1-219x300.png 219w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img2-1-768x1051.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img2-1-575x787.png 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img2-1.png 1046w\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img2-1-748x1024.png\" alt=\"blog slack env img2 1\" title=\"\"><\/p>\n\n\n\n<p><em>Slack \uc774\uc0c1 \uc774\ubca4\ud2b8 \ub300\uc751 \uae30\ubcf8 \uc124\uc815<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-to-collect-and-ingest-slack-audit-logs-with-sumo-logic\">Sumo Logic\uc73c\ub85c Slack \uac10\uc0ac \ub85c\uadf8\ub97c \uc218\uc9d1 \ubc0f \uc778\uc81c\uc2a4\ud2b8\ud558\ub294 \ubc29\ubc95<\/h2>\n\n\n\n<p>Sumo Logic\uc744 \uc0ac\uc6a9\ud558\uba74 Slack \uac10\uc0ac \ub85c\uadf8 \uc218\uc9d1\uc774 \ube44\uad50\uc801 \uac04\ub2e8\ud569\ub2c8\ub2e4. \uc774 \uac00\uc774\ub4dc\uc5d0\uc11c\ub294 Slack\uc5d0\uc11c \ub85c\uadf8\ub97c \uc218\uc9d1\ud558\ub294 <a href=\"https:\/\/help.sumologic.com\/docs\/send-data\/hosted-collectors\/cloud-to-cloud-integration-framework\/slack-source\/\" target=\"_blank\" rel=\"noreferrer noopener\">\uc804\uccb4 \uacfc\uc815\uc744 \uc548\ub0b4<\/a>\ud558\uaca0\uc9c0\ub9cc, \uadf8 \ub2e8\uacc4\uc758 \uac1c\uc694\ub97c \uac04\ub7b5\ud788 \uc694\uc57d\ud558\uba74 \ub2e4\uc74c\uacfc \uac19\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Slack Enterprise Grid \uacc4\uc815\uc744 \ubcf4\uc720\ud574\uc57c \ud569\ub2c8\ub2e4. Enterprise Grid \uacc4\uc815\uc774 \uc5c6\uc73c\uba74 Slack \uac10\uc0ac \ub85c\uadf8\ub97c \uc218\uc9d1\ud560 \uc218 \uc5c6\uc2b5\ub2c8\ub2e4.<\/li>\n\n\n\n<li><code>auditlogs:read<\/code> \uad8c\ud55c\uc744 \uac00\uc9c4 Slack \uc571\uc744 \uc0dd\uc131\ud569\ub2c8\ub2e4.<\/li>\n\n\n\n<li>\ud574\ub2f9 \uc571\uc744 Enterprise Grid\uc5d0 \uc124\uce58\ud569\ub2c8\ub2e4.<\/li>\n\n\n\n<li>Sumo Logic\uc758 Slack Cloud-to-Cloud Connector\ub97c \uc124\uce58 \ubc0f \uad6c\uc131\ud569\ub2c8\ub2e4.<\/li>\n\n\n\n<li>\uc911\uc694 \uc548\ub0b4: Slack \ub85c\uadf8 \uc18c\uc2a4 \uc124\uc815\uc5d0\uc11c \u201cForward to SIEM\u201d \uccb4\ud06c\ubc15\uc2a4\ub97c \uc120\ud0dd\ud558\uc5ec \ub85c\uadf8\uac00 SIEM\uc73c\ub85c \ud3ec\uc6cc\ub529\ub418\ub3c4\ub85d \uad6c\uc131\ud588\ub294\uc9c0 \ubc18\ub4dc\uc2dc \ud655\uc778\ud569\ub2c8\ub2e4.\u00a0\u00a0<\/li>\n<\/ol>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"784\" height=\"1024\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img3-1-784x1024.png\" alt=\"blog slack env img3 1\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img3-1-784x1024.png 784w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img3-1-230x300.png 230w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img3-1-768x1003.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img3-1-575x751.png 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img3-1.png 812w\" title=\"\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-security-analysts-can-use-slack-logs-for-threat-detection-investigation-and-response\">\ubcf4\uc548 \ubd84\uc11d\ud300\uc774 Slack \ub85c\uadf8\ub97c \ud65c\uc6a9\ud574 \uc704\ud611\uc744 \ud0d0\uc9c0\u00b7\uc870\uc0ac\u00b7\ub300\uc751\ud558\ub294 \ubc29\ubc95\u00a0<\/h2>\n\n\n\n<p>Slack\uc740 \uc790\uc0ac \ud50c\ub7ab\ud3fc\uc5d0\uc11c \ube44\uc815\uc0c1\uc801\uc778 \ud589\ub3d9\uc744 \uac10\uc9c0\ud558\uace0 \uc774\uc0c1 \uc774\ubca4\ud2b8\ub97c \uc0dd\uc131\ud568\uc73c\ub85c\uc368 \uace0\uac1d\uc5d0\uac8c \ub9e4\uc6b0 \uc720\uc6a9\ud55c \uc11c\ube44\uc2a4\ub97c \uc81c\uacf5\ud569\ub2c8\ub2e4. Slack\uc740 \uc790\uc0ac \ud50c\ub7ab\ud3fc\uc758 \ub3d9\uc791\uc744 \ub204\uad6c\ubcf4\ub2e4 \uc798 \uc774\ud574\ud558\uace0 \uc788\uae30 \ub54c\ubb38\uc5d0, \uc5b4\ub5a4 \ud589\ub3d9\uc744 \u2018\uc774\uc0c1 \ud589\ub3d9\u2019\uc73c\ub85c \uac04\uc8fc\ud574\uc57c \ud558\ub294\uc9c0\ub97c \uac00\uc7a5 \uc815\ud655\ud788 \ud310\ub2e8\ud560 \uc218 \uc788\ub294 \uc704\uce58\uc5d0 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<p>\uadf8\ub7ec\ub098 Slack \uc5d4\uc9c0\ub2c8\uc5b4\ub9c1 \ud300\uc740 \uc774\uc0c1 \uc774\ubca4\ud2b8\ub97c \uc0dd\uc131\ud558\uae30 \uc704\ud574 \uc0ac\uc6a9\ud558\ub294 \ud0d0\uc9c0 \uae30\uc900\uc744 \uc678\ubd80\uc5d0 \uacf5\uac1c\ud558\uc9c0 \uc54a\uc2b5\ub2c8\ub2e4. \uadf8 \uc774\uc720\ub294 \uba85\ud655\ud569\ub2c8\ub2e4. \uc774 \uae30\uc900\uc774 \uacf5\uac1c\ub420 \uacbd\uc6b0, \uacf5\uaca9\uc790\ub4e4\uc774 \uadf8 \uc815\ubcf4\ub97c \uc545\uc6a9\ud574 \ud0d0\uc9c0\ub97c \ud68c\ud53c\ud558\ub294 \ubc29\ubc95\uc744 \ud6e8\uc52c \uc27d\uac8c \uc124\uacc4\ud560 \uc218 \uc788\uae30 \ub54c\ubb38\uc785\ub2c8\ub2e4.<\/p>\n\n\n\n<p>\ud558\uc9c0\ub9cc \ubcf4\uc548 \ubd84\uc11d\uac00 \uc785\uc7a5\uc5d0\uc11c\ub294 \uc774 \uc810\uc774 \uae4c\ub2e4\ub85c\uc6b4 \uacfc\uc81c\uac00 \ub429\ub2c8\ub2e4. \uacbd\uace0\uac00 \uc65c \ud2b8\ub9ac\uac70\ub418\uc5c8\ub294\uc9c0\ub97c \uc815\ud655\ud788 \uc54c \uc218 \uc5c6\uc73c\uba74, \ud574\ub2f9 \uc774\uc0c1 \uc774\ubca4\ud2b8\ub97c \uc720\ubc1c\ud55c \uac10\uc0ac \ub85c\uadf8\ub97c \ucc3e\uc544\ub0b4\uae30 \uc704\ud574 \ucffc\ub9ac\ub97c \uc791\uc131\ud558\uace0 \uac80\uc99d\ud558\ub294 \ub370 \ub354 \ub9ce\uc740 \uc2dc\uac04\uc774 \uc18c\uc694\ub429\ub2c8\ub2e4. \ub610\ud55c, \ubd84\uc11d \ub85c\uc9c1\uc744 \ud29c\ub2dd\ud558\uac70\ub098 \uc624\ud0d0\uacfc \ubbf8\ud0d0\uc744 \ud3c9\uac00\ud558\ub294 \uacfc\uc815\ub3c4 \uadf8\ub9cc\ud07c \uae4c\ub2e4\ub85c\uc6cc\uc9c0\uace0, \uc77c\ubd80 \ub2e8\uacc4\uc5d0\uc11c\ub294 \ucd94\uce21\uc5d0 \uc758\uc874\ud574\uc57c \ud560 \uc218\ub3c4 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<p>\uc774\uc0c1 \uc774\ubca4\ud2b8\uc758 \uc885\ub958\uc5d0 \ub530\ub77c \ud2b8\ub9ac\uac70 \uc6d0\uc778\uc744 \ud30c\uc545\ud558\uae30 \uc26c\uc6b4 \uacbd\uc6b0\ub3c4 \uc788\uc9c0\ub9cc, \uadf8\ub807\uc9c0 \uc54a\uc740 \uacbd\uc6b0\ub3c4 \uc788\uc2b5\ub2c8\ub2e4. \uc608\ub97c \ub4e4\uc5b4, excessive_downloads(\uacfc\ub3c4\ud55c \ub2e4\uc6b4\ub85c\ub4dc)\uc640 \uac19\uc740 \uc774\ubca4\ud2b8\ub294 \ubc1c\uc0dd \uc6d0\uc778\uc774 \uba85\ud655\ud558\uc9c0 \uc54a\uc544, \uc774\ubca4\ud2b8 \ubc1c\uc0dd \uc804\ud6c4\uc758 \ub2e4\uc6b4\ub85c\ub4dc \ud65c\ub3d9\uc744 \uc9c1\uc811 \uac80\uc0c9\ud558\uac70\ub098, \ub2e4\uc6b4\ub85c\ub4dc\ub41c \ud30c\uc77c\uc758 \uc885\ub958\ub97c \uac80\ud1a0\ud558\uac70\ub098, \ud574\ub2f9 \uc0ac\uc6a9\uc790\uc758 \uc774\uc804 \uae30\uac04\uacfc \ube44\uad50\ud588\uc744 \ub54c \ub2e4\uc6b4\ub85c\ub4dc \uc591\uc774 \u2018\uc815\uc0c1\uc801\uc778\uc9c0\u2019\ub97c \ud3c9\uac00\ud574\uc57c \ud560 \uc218\ub3c4 \uc788\uc2b5\ub2c8\ub2e4.\u00a0<\/p>\n\n\n\n<p>\uc774\uc81c \uc774\ub7ec\ud55c \uc774\uc0c1 \uc774\ubca4\ud2b8\ub97c \uc2e4\uc81c\ub85c \uc5b4\ub5bb\uac8c \uc870\uc0ac\ud560 \uc218 \uc788\ub294\uc9c0 \uc0b4\ud3b4\ubcf4\uaca0\uc2b5\ub2c8\ub2e4.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"investigating-potential-cookie-theft-in-slack\">Slack\uc5d0\uc11c \ubc1c\uc0dd\ud560 \uc218 \uc788\ub294 \ucfe0\ud0a4 \ud0c8\ucde8 \uc758\uc2ec \uc0ac\ub840 \uc870\uc0ac\ud558\uae30\u00a0<\/h2>\n\n\n\n<p>EA \uce68\ud574 \uc0ac\ub840\ub85c \ub2e4\uc2dc \ub3cc\uc544\uac00 \ubd05\uc2dc\ub2e4. \uc774 \uc0ac\uac74\uc5d0\uc11c \uacf5\uaca9\uc790\ub294 \ub3c4\ub09c\ub41c \ucfe0\ud0a4\ub97c \uc774\uc6a9\ud574 \ub0b4\ubd80 \uc2dc\uc2a4\ud15c\uc5d0 \uc811\uadfc\ud588\uc2b5\ub2c8\ub2e4. \uadf8\ub807\ub2e4\uba74, \ub3c4\ub09c\ub41c \ucfe0\ud0a4\uac00 \uc7ac\uc0ac\uc6a9\ub420 \ub54c Slack\uc5d0\uc11c\ub294 \uc5b4\ub5a4 \uc774\uc0c1 \uc774\ubca4\ud2b8\uac00 \ubc1c\uc0dd\ud560 \uc218 \uc788\uc744\uae4c\uc694? \uadf8\ub9ac\uace0 \uc774\ub7ec\ud55c \uc774\uc0c1 \uc774\ubca4\ud2b8\uac00 \ub85c\uadf8\uc5d0 \ub0a8\ub294\ub2e4\uba74, \uc5b4\ub5bb\uac8c \uc870\uc0ac\ud560 \uc218 \uc788\uc744\uae4c\uc694?<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"understanding-slack-session-ids\">Slack \uc138\uc158 ID \uc774\ud574\ud558\uae30<\/h3>\n\n\n\n<p>\uc0ac\uc6a9\uc790\uac00 Slack\uc5d0 \ub85c\uadf8\uc778\ud560 \ub54c\ub9c8\ub2e4 \uc138\uc158 ID\uac00 \uc0dd\uc131\ub429\ub2c8\ub2e4. \uc774 \uc138\uc158\uc740 \uc0ac\uc6a9\uc790\uc758 \uae30\uae30 \uc548\uc5d0 \ucfe0\ud0a4\ub85c \uc800\uc7a5\ub418\uc5b4 \uc720\uc9c0\ub429\ub2c8\ub2e4. \uc77c\ubc18\uc801\uc73c\ub85c \uac01 \uc138\uc158 ID\ub294 \ub2e8\uc77c \uae30\uae30\uc5d0\ub9cc \ub9e4\ud551\ub418\uc5b4\uc57c \ud569\ub2c8\ub2e4. \ub9cc\uc57d \ucfe0\ud0a4\uac00 \ud0c8\ucde8\ub418\uc5b4 \ub2e4\ub978 \uae30\uae30\uc5d0\uc11c \uc0ac\uc6a9\ub41c\ub2e4\uba74, \ub2e4\uc74c\uacfc \uac19\uc740 \ub85c\uadf8 \uc544\ud2f0\ud329\ud2b8\uc5d0\uc11c \ucc28\uc774\ub97c \ud655\uc778\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8 \ubb38\uc790\uc5f4<\/li>\n\n\n\n<li>IP \uc8fc\uc18c \ubc0f \uc704\uce58<\/li>\n\n\n\n<li>TLS \ud578\ub4dc\uc170\uc774\ud06c(ja3 \uc9c0\ubb38)\u00a0<\/li>\n<\/ul>\n\n\n\n<p>\uc774\ub7ec\ud55c \uc2e0\ud638\ub4e4\uc740 \ub3c4\ub09c\ub41c \ucfe0\ud0a4\uc758 \uc7ac\uc0ac\uc6a9 \uc5ec\ubd80\ub97c \uc2dd\ubcc4\ud558\ub294 \ub370 \uc720\uc6a9\ud55c \ub2e8\uc11c\uac00 \ub420 \uc218 \uc788\uc2b5\ub2c8\ub2e4. \ub2e4\ub9cc \uc8fc\uc758\ud560 \uc810\uc740, Slack \uac10\uc0ac \ub85c\uadf8\ub294 \uc0c1\ud638\uc791\uc6a9(interactive action)\uc774 \ubc1c\uc0dd\ud588\uc744 \ub54c\ub9cc \uc0dd\uc131\ub41c\ub2e4\ub294 \uac83\uc785\ub2c8\ub2e4. \uc989, \ud074\ub9ad\uc774\ub098 \ub2e4\uc6b4\ub85c\ub4dc \uc5c6\uc774 \ub2e8\uc21c\ud788 \uba54\uc2dc\uc9c0\ub97c \uc77d\ub294 \uc218\ub3d9\uc801 \uc811\uadfc\uc740 \ub85c\uadf8\uc5d0 \uae30\ub85d\ub418\uc9c0 \uc54a\uc744 \uc218 \uc788\uc2b5\ub2c8\ub2e4. \ub530\ub77c\uc11c \ucfe0\ud0a4 \uc7ac\uc0ac\uc6a9 \uc5ec\ubd80 \ud0d0\uc9c0\ub294 \uc0ac\uc6a9\uc790\uc758 \uc2e4\uc81c \ud65c\ub3d9 \ud615\ud0dc\uc5d0 \ub530\ub77c \ub2ec\ub77c\uc9d1\ub2c8\ub2e4.<\/p>\n\n\n\n<p>\uc774\ub7ec\ud55c \ucc28\uc774\uc810\ub4e4\uc740 \ub3d9\uc77c\ud55c \uc138\uc158 ID\uc640 \uad00\ub828\ub41c \ub85c\uadf8\uc5d0\uc11c \ud655\uc778\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"186\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img4-1-1024x186.png 1024w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img4-1-300x55.png 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img4-1-768x140.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img4-1-575x105.png 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img4-1.png 1230w\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img4-1-1024x186.png\" alt=\"blog slack env img4 1\" title=\"\"><\/p>\n\n\n\n<p><em>Sumo Logic Cloud SIEM \ub808\ucf54\ub4dc\uc5d0 \ud45c\uc2dc\ub41c Slack \uc138\uc158 ID \uc608\uc2dc<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"anomaly-events-that-could-signal-cookie-theft\">\ucfe0\ud0a4 \ud0c8\ucde8\ub97c \uc2dc\uc0ac\ud560 \uc218 \uc788\ub294 \uc774\uc0c1 \uc774\ubca4\ud2b8<\/h3>\n\n\n\n<p>\ucfe0\ud0a4 \ud0c8\ucde8\ub85c \uc778\ud574 \ud2b8\ub9ac\uac70\ub420 \uc218 \uc788\ub294 <a href=\"https:\/\/api.slack.com\/admins\/audit-logs-anomaly\" target=\"_blank\" rel=\"noreferrer noopener\">Slack \uc774\uc0c1 \uc774\ubca4\ud2b8<\/a> \ubaa9\ub85d\uc744 \uc0b4\ud3b4\ubcf4\uba74 \ub2e4\uc74c\uacfc \uac19\uc740 \ud6c4\ubcf4\ub4e4\uc774 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>ASN<\/code><\/li>\n\n\n\n<li><code>ip_address(IP \uc8fc\uc18c)<\/code><\/li>\n\n\n\n<li><code>session_fingerprint(\uc138\uc158 \uc9c0\ubb38)<\/code><\/li>\n\n\n\n<li><code>tor<\/code><\/li>\n\n\n\n<li><code>unexpected_client(\uc608\uc0c1\uce58 \ubabb\ud55c \ud074\ub77c\uc774\uc5b8\ud2b8)<\/code><\/li>\n\n\n\n<li><code>unexpected_user_agent(\uc608\uc0c1\uce58 \ubabb\ud55c \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8)<\/code><\/li>\n\n\n\n<li><code>user_agent(\uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8)<\/code><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"hunt-for-potential-cookie-theft-using-sumo-logic\">Sumo Logic\uc744 \uc774\uc6a9\ud55c \ucfe0\ud0a4 \ud0c8\ucde8 \ud0d0\uc9c0<\/h3>\n\n\n\n<p>\uc774\uc81c \uc704\uc758 \uc815\ubcf4\ub97c \ubc14\ud0d5\uc73c\ub85c, \uc9c0\ub09c 2\uc8fc\uac04 \uc6b0\ub9ac \ud658\uacbd\uc5d0\uc11c \ubc1c\uc0dd\ud55c Slack \uc774\uc0c1 \uc774\ubca4\ud2b8 \uc804\uccb4\ub97c \ud3ed\ub113\uac8c \uc870\ud68c\ud574 \ubcf4\uaca0\uc2b5\ub2c8\ub2e4. \ub2e4\uc74c \uac80\uc0c9 \ucffc\ub9ac\ub294 \ubaa8\ub4e0 Slack \uc774\uc0c1 \uc774\ubca4\ud2b8\ub97c \uac00\uc838\uc640 \ubc1c\uc0dd \uc6d0\uc778\ubcc4\ub85c \uadf8\ub8f9\ud654\ud55c \uac83\uc785\ub2c8\ub2e4.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">_index=sec_record_notification metadata_vendor=\"Slack\" metadata_deviceEventId=\"anomaly\"\n| count by threat_signalName<\/pre>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"635\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img5-1-1024x635.png\" alt=\"blog slack env img5 1\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img5-1-1024x635.png 1024w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img5-1-300x186.png 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img5-1-768x476.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img5-1-575x356.png 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img5-1.png 1094w\" title=\"\"><\/p>\n\n\n\n<p><em>\uadf8\ub9bc 4: \uc6d0\uc778\ubcc4\ub85c \uadf8\ub8f9\ud654\ud55c Slack \uc774\uc0c1 \uc774\ubca4\ud2b8<\/em><\/p>\n\n\n\n<p>\uac80\uc0c9 \uacb0\uacfc, \ucd1d 323\uac74\uc758 \uc774\ubca4\ud2b8\uac00 \uac80\uc0c9\ub418\uc5c8\uc2b5\ub2c8\ub2e4. \uc5ec\uae30\uc11c \uc8fc\ubaa9\ud560 \uc810\uc740 \ub450 \uac00\uc9c0\uc785\ub2c8\ub2e4.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\ud55c \uc774\ubca4\ud2b8\uc5d0 \ubcf5\uc218\uc758 \ubc1c\uc0dd \uc6d0\uc778\uc774 \uc0dd\uae38 \uc218 \uc788\uc2b5\ub2c8\ub2e4. \uc608\ub97c \ub4e4\uc5b4, <code>asn|ip_address<\/code> \ub610\ub294 <code>unexpected_user_agent|user_agent<\/code>\uc640 \uac19\uc740 \ud615\ud0dc\ub85c \ud45c\uc2dc\ub429\ub2c8\ub2e4.<\/li>\n\n\n\n<li>\uac00\uc7a5 \ube48\ub3c4\uac00 \ub192\uc740 \uc774\uc0c1 \uc774\ubca4\ud2b8 \uc6d0\uc778\uc740 asn|ip_address\uc785\ub2c8\ub2e4. \uc774\ub7ec\ud55c \uc774\ubca4\ud2b8\ub294 API\ub97c \ud1b5\ud574 \ud5c8\uc6a9\ub41c \uc790\uc728 \uc2dc\uc2a4\ud15c \ubc88\ud638(ASN) \ubc0f IP \uc8fc\uc18c \ubc94\uc704\ub97c\u00a0<a href=\"https:\/\/api.slack.com\/admins\/audit-logs-anomaly#exclude\" target=\"_blank\" rel=\"noreferrer noopener\">\uc81c\uc678 \ubaa9\ub85d<\/a>\uc5d0 \ucd94\uac00\ud558\uc5ec \ud29c\ub2dd\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/li>\n<\/ul>\n\n\n\n<p>\uc774\ubc88\uc5d0\ub294 <code>unexpected_user_agent<\/code>\uc640 <code>user_agent<\/code> \uc774\ubca4\ud2b8\uc5d0 \ucd08\uc810\uc744 \ub9de\ucd94\uc5b4 \ub3c4\ub09c\ub41c \ucfe0\ud0a4\uc640 \uad00\ub828\ub41c \ud65c\ub3d9\uc744 \ucd94\uc801\ud558\uaca0\uc2b5\ub2c8\ub2e4. \uc774\ub97c \uc704\ud574 \ub2e4\uc74c \ucffc\ub9ac\ub97c \uc0ac\uc6a9\ud558\uc5ec \ud574\ub2f9 \uc774\ubca4\ud2b8\uc640 \uadf8 \uc138\uc158 ID\ub97c \uc870\ud68c\ud569\ub2c8\ub2e4.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">_index=sec_record_notification metadata_vendor=\"Slack\" metadata_deviceEventId=\"anomaly\"\n| where threat_signalName = \"Anomaly Event : unexpected_user_agent|user_agent\"\n| count by sessionId<\/pre>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"810\" height=\"410\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img6-1.png\" alt=\"blog slack env img6 1\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img6-1.png 810w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img6-1-300x152.png 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img6-1-768x389.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img6-1-575x291.png 575w\" title=\"\"><\/p>\n\n\n\n<p><em><code>unexpected_user_agent<\/code> \uc774\uc0c1 \uc774\ubca4\ud2b8\uc758 \uc138\uc158 ID<\/em><\/p>\n\n\n\n<p>\uc774\uc81c \uc870\uc0ac\ud560 \ub300\uc0c1\uc774 \ub418\ub294 \uc774\uc0c1 \uc774\ubca4\ud2b8\ub97c \ud655\ubcf4\ud588\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<p>\ub530\ub77c\uc11c \uc774\ubca4\ud2b8\uc758 \uc138\ubd80 \uc815\ubcf4\ub97c \uac80\ud1a0\ud558\uba70 \uc774\ubca4\ud2b8\uac00 \uc65c \ud2b8\ub9ac\uac70\ub418\uc5c8\ub294\uc9c0\uc5d0 \ub300\ud55c \ub9e5\ub77d(context)\uc744 \ud30c\uc545\ud574 \ubcf4\uaca0\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"857\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img7-1-1024x857.png 1024w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img7-1-300x251.png 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img7-1-768x643.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img7-1-575x481.png 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img7-1.png 1432w\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img7-1-1024x857.png\" alt=\"blog slack env img7 1\" title=\"\"><\/p>\n\n\n\n<p><em><code>unexpected_user_agent|user_agent<\/code> \uc774\uc0c1 \uc774\ubca4\ud2b8\uc5d0 \ub300\ud55c \uc138\ubd80 \uc815\ubcf4<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"analyzing-the-anomaly-event\">\uc774\uc0c1 \uc774\ubca4\ud2b8 \ubd84\uc11d\ud558\uae30<\/h3>\n\n\n\n<p>\uc774\uc0c1 \uc774\ubca4\ud2b8\uc758 <code>\uc138\ubd80<\/code> \uba54\ud0c0\ub370\uc774\ud130\ub294 \uc774\ubca4\ud2b8\uac00 \ud2b8\ub9ac\uac70\ub41c \uc774\uc720\ub97c \ubcf4\uc5ec\uc90d\ub2c8\ub2e4. \uc774\ubc88 \uc0ac\ub840\uc5d0\uc11c\ub294 IP \uc8fc\uc18c\uc640 \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8\uac00 \ubcc0\uacbd\ub41c \uac83\uc774 \uc6d0\uc778\uc774\uc5c8\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<p>  <strong>IP \uc8fc\uc18c \ubcc0\uacbd<\/strong>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\ud604\uc7ac IP \uc8fc\uc18c:\u00a0<code>172.59.222.55<\/code><\/li>\n\n\n\n<li>\uc774\uc804 IP \uc8fc\uc18c:\u00a0<code>204.16.138.54<\/code><\/li>\n<\/ul>\n\n\n\n<p>\uc774 IP \uc8fc\uc18c \ubcc0\uacbd\uc740 \uae30\uae30\uac00 \ubc14\ub00c\uc5c8\ub2e4\ub294 \ub73b\uc77c\uae4c\uc694? \uc989, \uc0ac\uc6a9\uc790\uc758 \uae30\uae30\uc5d0\uc11c \uacf5\uaca9\uc790\uc758 \uae30\uae30\ub85c \uc804\ud658\ub418\uc5c8\uc744 \uac00\ub2a5\uc131\uc774 \uc788\uc744\uae4c\uc694? \uadf8\ub7f4 \uac00\ub2a5\uc131\ub3c4 \uc788\uc9c0\ub9cc, \uc774 \uacbd\uc6b0\uc5d0\ub294 \ud574\ub2f9 \uae30\uae30\uac00 \ubaa8\ubc14\uc77c \uae30\uae30\uc774\uba70, GeoIP \uc815\ubcf4\uc0c1 \ub450 \uc8fc\uc18c \ubaa8\ub450 \ub178\uc2a4\uce90\ub864\ub77c\uc774\ub098\uc8fc \uc0ec\ub7ff(Charlotte, North Carolina) \uc9c0\uc5ed\uc5d0 \uc18d\ud558\ubbc0\ub85c \uae30\uae30\uac00 \ubc14\ub00c\uc5c8\uc744 \uac00\ub2a5\uc131\uc740 \ub0ae\ub2e4\uace0 \ud310\ub2e8\ub429\ub2c8\ub2e4.<\/p>\n\n\n\n<p><strong>\uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8 \ubcc0\uacbd<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\ud604\uc7ac \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8: &#8220;<code>AppleCoreMedia\/1.0.0.21F90(iPhone; U; CPU OS 17_5_1 \uac19\uc740 Mac OS X; en_us)<\/code>&#8220;<\/li>\n\n\n\n<li>\uc774\uc804 \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8: &#8220;<code>com.tinyspeck.chatlyio\/25.04.10 (iPhone; iOS 17.5.1; Scale\/3.00)<\/code>&#8220;<\/li>\n<\/ul>\n\n\n\n<p>\uc774 \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8\uc758 \ubcc0\uacbd\uc740 \uae30\uae30\uc758 \ubcc0\uacbd\uc744 \uc758\ubbf8\ud560\uae4c\uc694?<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8 \ubb38\uc790\uc5f4\uc774 \uc2a4\ud478\ud551\ub418\uc9c0 \uc54a\uc558\ub2e4\uace0 \uac00\uc815\ud558\uba74, \ub450 \uac12 \ubaa8\ub450 iOS 18.4 \ubc84\uc804\uc744 \uc0ac\uc6a9\ud558\ub294 iPhone\uc5d0\uc11c \ubc1c\uc0dd\ud55c \uac83\uc73c\ub85c \ubcf4\uc785\ub2c8\ub2e4.\u00a0<\/li>\n\n\n\n<li>Tiny Speck\uc740 Slack\uc744 \uac1c\ubc1c\ud55c \ud68c\uc0ac\uc758 \uc6d0\ub798 \uc774\ub984\uc785\ub2c8\ub2e4. \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8 \ubb38\uc790\uc5f4 <code>com.tinyspeck.chatlyio\/25.04.10<\/code>\ub294 Slack iOS \ud074\ub77c\uc774\uc5b8\ud2b8\uc5d0 \ud574\ub2f9\ud560 \uac00\ub2a5\uc131\uc774 \ub192\uc2b5\ub2c8\ub2e4. <br\/><code>AppleCoreMedia<\/code>\ub294 iOS\uc5d0\uc11c \uc2a4\ud2b8\ub9ac\ubc0d \ubc0f \ubbf8\ub514\uc5b4 \uc7ac\uc0dd\uc744 \ucc98\ub9ac\ud558\ub294 \ub370 \uc0ac\uc6a9\ub418\ub294 \ud504\ub808\uc784\uc6cc\ud06c\uc785\ub2c8\ub2e4.<\/li>\n\n\n\n<li>\uc774 \uc810\uc744 \uac10\uc548\ud558\uba74, Slack \ub0b4\uc5d0\uc11c \ub3d9\uc601\uc0c1 \ub4f1 \ubbf8\ub514\uc5b4 \ud30c\uc77c\uc744 \uc2a4\ud2b8\ub9ac\ubc0d\ud560 \ub54c\ub294 AppleCoreMedia \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8\uac00 \ub098\ud0c0\ub098\uace0, \uc77c\ubc18\uc801\uc778 Slack \uc0ac\uc6a9 \uc2dc\uc5d0\ub294 Tiny Speck \uc5d0\uc774\uc804\ud2b8\uac00 \uae30\ub85d\ub418\ub294 \uac83\uc73c\ub85c \ubcf4\uc785\ub2c8\ub2e4. \uacf5\uc2dd \ubb38\uc11c\uc5d0 \uc774\ub7ec\ud55c \ub3d9\uc791\uc774 \uba85\uc2dc\ub418\uc5b4 \uc788\uc9c0\ub294 \uc54a\uc9c0\ub9cc, \ub85c\uadf8 \ubd84\uc11d \uacb0\uacfc\ub294 \uc774\ub7ec\ud55c \ud574\uc11d\uc744 \ub4b7\ubc1b\uce68\ud569\ub2c8\ub2e4.<\/li>\n\n\n\n<li>AppleCoreMedia\ub294 iOS\uc5d0\uc11c \uc2a4\ud2b8\ub9ac\ubc0d \ubbf8\ub514\uc5b4\ub97c \uc704\ud574 \uc0ac\uc6a9\ub429\ub2c8\ub2e4.<\/li>\n<\/ul>\n\n\n\n<p>\uc989, AppleCoreMedia\ub294 iOS\uc758 \uc2a4\ud2b8\ub9ac\ubc0d \ubbf8\ub514\uc5b4 \ucc98\ub9ac\uc6a9, Tiny Speck\uc740 \uc77c\ubc18\uc801\uc778 Slack \uc0ac\uc6a9 \ud65c\ub3d9\uc744 \ubc18\uc601\ud558\ub294 \uc5d0\uc774\uc804\ud2b8\uc77c \uac00\ub2a5\uc131\uc774 \ud07d\ub2c8\ub2e4.<\/p>\n\n\n\n<p>\uc774 \uac00\uc124\uc744 \uac80\uc99d\ud558\uae30 \uc704\ud574, \uc774\uc0c1 \uc774\ubca4\ud2b8\uc5d0 \ud3ec\ud568\ub41c \uac1c\ubcc4 \ub85c\uadf8\ub97c \uac80\ud1a0\ud574 \ubcf4\uaca0\uc2b5\ub2c8\ub2e4. \uc138\uc158 ID\ub97c \uac80\uc0c9\ud558\uace0 \uac01 \ud65c\ub3d9\uacfc \uc5f0\uad00\ub41c \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8\ub97c \ud655\uc778\ud569\ub2c8\ub2e4.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">(_index=sec_record_notification OR _index=sec_record_audit) metadata_vendor=\"Slack\" sessionId=8475310491012\n| fields action, http_userAgent<\/pre>\n\n\n\n<p>\uc138\uc158\uc740 \uc7a5\uae30\uac04 \uc720\uc9c0\ub420 \uc218 \uc788\uc73c\ubbc0\ub85c, \uac80\uc0c9 \uc2dc \uc2dc\uac04 \ubc94\uc704\ub97c \ub109\ub109\ud788 \uc124\uc815\ud558\ub294 \uac83\uc774 \uc88b\uc2b5\ub2c8\ub2e4. \uc774\ubc88 \uc0ac\ub840\uc758 \uc138\uc158\uc740 90\uc77c \uc774\uc0c1 \uc720\uc9c0\ub418\uc5c8\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"387\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img8-1-1024x387.png 1024w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img8-1-300x113.png 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img8-1-768x290.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img8-1-1536x581.png 1536w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img8-1-575x217.png 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img8-1.png 1600w\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img8-1-1024x387.png\" alt=\"blog slack env img8 1\" title=\"\"><\/p>\n\n\n\n<p><em>\uac10\uc0ac\ub41c Slack \ud65c\ub3d9 \ubc0f \uad00\ub828 \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8 \ubb38\uc790\uc5f4<\/em><\/p>\n\n\n\n<p>2025\ub144 4\uc6d4 9\uc77c\uc5d0 \ubc1c\uc0dd\ud55c \uc774\uc0c1 \uc774\ubca4\ud2b8 \uc774\uc804 \uba70\uce60\uac04\uc758 \ub85c\uadf8\ub97c \uc9d1\uc911\uc801\uc73c\ub85c \uc0b4\ud3b4\ubcf4\uaca0\uc2b5\ub2c8\ub2e4. \uc774\uc0c1 \uc774\ubca4\ud2b8\uac00 \ubc1c\uc0dd\ud558\uae30 \uc57d \ud55c \uc2dc\uac04 \uc804, \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8\uac00 Tiny Speck(Slack) \uc5d0\uc774\uc804\ud2b8\uc5d0\uc11c AppleCoreMedia\ub85c \ubcc0\uacbd\ub418\uc5c8\uc2b5\ub2c8\ub2e4. \uadf8 \uc774\uc720\ub294 \ubb34\uc5c7\uc77c\uae4c\uc694? \uc544\ub9c8\ub3c4 <code>file_downloaded<\/code>\uc5d0\uc11c \ub2e4\uc6b4\ub85c\ub4dc\ub41c \ud30c\uc77c\uc758 \uc720\ud615\uc774 \uc2a4\ud2b8\ub9ac\ubc0d\uc744 \ud544\uc694\ub85c \ud588\uae30 \ub54c\ubb38\uc77c \uac83\uc785\ub2c8\ub2e4. \uc774\ub97c \ud655\uc778\ud558\uae30 \uc704\ud574, \uac80\uc0c9 \uacb0\uacfc \ud45c\uc2dc \ud56d\ubaa9\uc5d0 <code>file_mimetype<\/code> \ud544\ub4dc\ub97c \ucd94\uac00\ud569\ub2c8\ub2e4. \ud544\ub4dc \ubaa9\ub85d\uc5d0\uc11c \uc228\uae40 \ud544\ub4dc \uc139\uc158\uc744 \uc5f4\uace0 \ud574\ub2f9 \ud544\ub4dc\uba85\uc744 \uc120\ud0dd\ud569\ub2c8\ub2e4.<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"664\" height=\"738\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img9-1.png 664w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img9-1-270x300.png 270w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img9-1-575x639.png 575w\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img9-1.png\" alt=\"blog slack env img9 1\" title=\"\"><\/p>\n\n\n\n<p><em>\ud544\ub4dc 8: \uac80\uc0c9 \uacb0\uacfc \ud45c\uc2dc\uc5d0 file_mimeType \ud544\ub4dc \ucd94\uac00<\/em><\/p>\n\n\n\n<p><code>file_mimeType<\/code>\uc744 \ud45c\uc2dc\ud55c \uacb0\uacfc, MP4 \ud30c\uc77c\uc744 \ub2e4\uc6b4\ub85c\ub4dc\ud560 \ub54c\ub294 AppleCoreMedia, JPG \ud30c\uc77c\uc744 \ub2e4\uc6b4\ub85c\ub4dc\ud560 \ub54c\ub294 Tiny Speck \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8\uac00 \uc0ac\uc6a9\ub41c\ub2e4\ub294 \uc0ac\uc2e4\uc744 \uba85\ud655\ud788 \ud655\uc778\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"351\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img10-1-1024x351.png 1024w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img10-1-300x103.png 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img10-1-768x263.png 768w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img10-1-1536x526.png 1536w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img10-1-575x197.png 575w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img10-1.png 1600w\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/\/blog-slack-env-img10-1-1024x351.png\" alt=\"blog slack env img10 1\" title=\"\"><\/p>\n\n\n\n<p><em>\uadf8\ub9bc 9: \ub2e4\uc6b4\ub85c\ub4dc\ud55c \ud30c\uc77c \uc720\ud615\uacfc \uc5f0\uad00\ub41c \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8 \ubb38\uc790\uc5f4 \ubd84\uc11d<\/em><\/p>\n\n\n\n<p>\uc774 \uacbd\uc6b0, Slack \uc774\uc0c1 \uc774\ubca4\ud2b8\uc5d0\uc11c \uc545\uc758\uc801\uc778 \ud589\uc704\ub97c \ubc1c\uacac\ud558\uc9c0 \ubabb\ud588\uc2b5\ub2c8\ub2e4. \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8\uac00 \ubcc0\uacbd\ub41c \uc138\uc158\uc774 \uc788\uc5c8\uc9c0\ub9cc, \uc774\ub294 \ub3d9\uc77c\ud55c \uc138\uc158 \ucfe0\ud0a4\ub97c \uc5ec\ub7ec \uae30\uae30\uc5d0\uc11c \uc0ac\uc6a9\ud588\uae30 \ub54c\ubb38\uc774 \uc544\ub2c8\ub77c, \ud30c\uc77c \uc720\ud615\uc758 \ucc28\uc774\ub85c \uc778\ud574 Slack \ub0b4\uc5d0\uc11c \uc11c\ub85c \ub2e4\ub978 \ud504\ub85c\uc138\uc2a4\uac00 \ud638\ucd9c\ub41c \uacb0\uacfc\uc600\uc2b5\ub2c8\ub2e4.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"using-slack-anomaly-event-types-for-custom-analytic-content\">Slack \uc774\uc0c1 \uc774\ubca4\ud2b8 \uc720\ud615\uc744 \ud65c\uc6a9\ud55c \ub9de\ucda4\ud615 \ubd84\uc11d \ucf58\ud150\uce20 \uc81c\uc791<\/h2>\n\n\n\n<p>Slack\uc740 \uc774\uc0c1 \uc774\ubca4\ud2b8\ub97c \ud0d0\uc9c0\ud558\uae30 \uc704\ud55c \uc815\ud655\ud55c \ub85c\uc9c1\uc744 \uacf5\uac1c\ud558\uc9c0 \uc54a\uc2b5\ub2c8\ub2e4. \uc774\ub294 \ubcf4\uc548\uc0c1 \ud0c0\ub2f9\ud55c \uc811\uadfc\uc785\ub2c8\ub2e4. \ud558\uc9c0\ub9cc <a href=\"https:\/\/api.slack.com\/admins\/audit-logs-anomaly\" target=\"_blank\" rel=\"noreferrer noopener\">\uc774\uc0c1 \uc774\ubca4\ud2b8 \uc720\ud615(anomaly event types)<\/a> \uc790\uccb4\ub294 \ub300\uc2dc\ubcf4\ub4dc, \ud5cc\ud305, \ub9de\ucda4\ud615 \ubd84\uc11d \uaddc\uce59\uc744 \uc124\uacc4\ud560 \ub54c \uc88b\uc740 \ucc38\uace0 \uc790\ub8cc\uac00 \ub429\ub2c8\ub2e4.<\/p>\n\n\n\n<p>\uc774\ub97c \ud65c\uc6a9\ud558\uba74 \ub2e4\uc74c\uacfc \uac19\uc740 \ud65c\ub3d9\uc744 \ubaa8\ub2c8\ud130\ub9c1\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\uc77c\ubc18\uc801\uc774\uc9c0 \uc54a\uc740 \uad00\ub9ac\uc790 \ud589\uc704: <a href=\"https:\/\/help.sumologic.com\/docs\/cse\/rules\/write-first-seen-rule\/\" target=\"_blank\" rel=\"noreferrer noopener\">\ucd5c\ucd08 \uac10\uc9c0 \uaddc\uce59(First Seen rule) \uc801\uc6a9<\/a><\/li>\n\n\n\n<li>\ub2e4\uc6b4\ub85c\ub4dc, \ud30c\uc77c \uacf5\uc720, \uba54\uc2dc\uc9c0 \uc0ad\uc81c \ub4f1\uc758 \uae09\uaca9\ud55c \uc99d\uac00: <a href=\"https:\/\/help.sumologic.com\/docs\/cse\/rules\/write-outlier-rule\/\" target=\"_blank\" rel=\"noreferrer noopener\">\uc544\uc6c3\ub77c\uc774\uc5b4 \uaddc\uce59(Outlier Rules) \uc801\uc6a9<\/a><\/li>\n<\/ul>\n\n\n\n<p>\ub2e4\uc2dc \ucfe0\ud0a4 \ud0c8\ucde8 \uc8fc\uc81c\ub85c \ub3cc\uc544\uac00\uc11c, \ud558\ub098\uc758 Slack \uc138\uc158\uc5d0\uc11c \ubcf5\uc218\uc758 \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8 \ubb38\uc790\uc5f4\uc774 \uc0ac\uc6a9\ub41c \uacbd\uc6b0\ub97c \ud5cc\ud305\ud558\ub824\uba74 \uc5b4\ub5bb\uac8c \ud574\uc57c \ud560\uae4c\uc694? \ub2e4\uc74c\uacfc \uac19\uc774 <a href=\"https:\/\/help.sumologic.com\/docs\/search\/search-query-language\/group-aggregate-operators\/count-count-distinct-and-count-frequent\/#count_distinct\" target=\"_blank\" rel=\"noreferrer noopener\">count_distinct<\/a> \uc5f0\uc0b0\uc790\ub97c \uc0ac\uc6a9\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">(_index=sec_record_notification OR _index=sec_record_audit) metadata_vendor=\"Slack\" metadata_product=\"Slack\"\u00a0\n| count_distinct(http_userAgent) by sessionId\n| sort by _count_distinct<\/pre>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"698\" height=\"616\" src=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img11-1.png\" alt=\"blog slack env img11 1\" srcset=\"https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img11-1.png 698w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img11-1-300x265.png 300w, https:\/\/www.sumologic.com\/wp-content\/uploads\/blog-slack-env-img11-1-575x507.png 575w\" title=\"\"><\/p>\n\n\n\n<p><em><code>\uc138\uc158 ID<\/code>\ub2f9 \uace0\uc720 \uc0ac\uc6a9\uc790 \uc5d0\uc774\uc804\ud2b8 \ubb38\uc790\uc5f4 \uac1c\uc218<\/em><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>\uc774\ub807\uac8c \uad00\uc2ec \uc788\ub294 \uc138\uc158\uc744 \ucc3e\uc544\ub0b8 \ud6c4, \uc544\ub798\uc640 \uac19\uc740 \ucffc\ub9ac\ub97c \uc0ac\uc6a9\ud574 \ud574\ub2f9 \uc138\uc158\uc758 \ubaa8\ub4e0 \ub85c\uadf8\ub97c \ub2e4\uc2dc \uc870\ud68c\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">(_index=sec_record_notification OR _index=sec_record_audit) metadata_vendor=\"Slack\" sessionId=[insert session ID here]\n| count by http_userAgent<\/pre>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"stay-ahead-of-slack-based-threats\">Slack \uae30\ubc18 \uc704\ud611\uc5d0 \ud55c\ubc1c \uc55e\uc120 \ub300\uc751<\/h2>\n\n\n\n<p>Slack\uc740 \uae30\uc5c5 \ub0b4\ubd80\uc758 \ub2e4\uc591\ud55c \uc815\ubcf4\uac00 \uc624\uac00\ub294 \ud50c\ub7ab\ud3fc\uc73c\ub85c, \ud574\ucee4\ub4e4\uc5d0\uac8c\ub294 \ub9e4\ub825\uc801\uc778 \uacf5\uaca9 \ub300\uc0c1\uc785\ub2c8\ub2e4. \uc774\uc0c1 \uc774\ubca4\ud2b8\ub97c \ud3ec\ud568\ud55c Slack \uac10\uc0ac \ub85c\uadf8\ub97c \ubaa8\ub2c8\ud130\ub9c1\ud558\ub294 \uac83\uc740 \uce68\ud574\ub97c \uc870\uae30\uc5d0 \uac10\uc9c0\ud558\ub294 \ub370 \ub9e4\uc6b0 \uc911\uc694\ud569\ub2c8\ub2e4.\u00a0<\/p>\n\n\n\n<p>Sumo Logic\uc740 \uc774\ub7ec\ud55c \ub85c\uadf8\ub97c \uc190\uc27d\uac8c \uc218\uc9d1, \ubd84\uc11d, \ub300\uc751\ud560 \uc218 \uc788\ub3c4\ub85d \uc9c0\uc6d0\ud569\ub2c8\ub2e4. \uc774\ub97c \ud1b5\ud574 \ubcf4\uc548 \ud300\uc740 \uc704\ud611\uc5d0 \ud55c\ubc1c \uc55e\uc11c \ub300\uc751\ud560 \uc218 \uc788\uc2b5\ub2c8\ub2e4.\u00a0<\/p>\n\n\n\n<p>Sumo Logic Cloud SIEM\uc5d0 \ub300\ud574 \ub354 \uc790\uc138\ud788 \uc54c\uc544\ubcf4\ub824\uba74, <a href=\"https:\/\/www.sumologic.com\/ko\/demo\/complete-threat-detection-investigation-and-response-demo\">\ub300\ud654\ud615 Cloud SIEM \ub370\ubaa8\ub97c \ud655\uc778\ud574 \ubcf4\uc138\uc694.\u00a0<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div><\/section>\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":332,"featured_media":45921,"template":"","meta":{"_acf_changed":false,"show_custom_date":false,"custom_date":"","featured":false,"featured_image":0,"learn_more_label":"","image_alt_text":"","learn_more_type":"","show_popup":false,"learn_more_link_file":0,"event_date":false,"event_start_date":"","event_end_date":"","place_holder_image_url":"","post_reading_time":"2","notification_enabled":false,"notification_text":"","notification_logo":"","notification_expiration_time":0,"is_enable_transparent_header":false,"selected_taxonomy_terms":{"blog-category":[325],"blog-tag":[],"translation_priority":[221]},"selected_primary_terms":[],"learn_more_link":[],"featured_page_list":[],"notification_enabled_post_list":[],"_gspb_post_css":"","_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"62715,62740,62708","_relevanssi_noindex_reason":"","inline_featured_image":false,"footnotes":""},"blog-category":[325],"blog-tag":[],"class_list":["post-55119","blog","type-blog","status-publish","has-post-thumbnail","hentry","blog-category-cloud-siem"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/blog\/55119","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/blog"}],"about":[{"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/types\/blog"}],"author":[{"embeddable":true,"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/users\/332"}],"version-history":[{"count":9,"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/blog\/55119\/revisions"}],"predecessor-version":[{"id":70222,"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/blog\/55119\/revisions\/70222"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/media\/45921"}],"wp:attachment":[{"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/media?parent=55119"}],"wp:term":[{"taxonomy":"blog-category","embeddable":true,"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/blog-category?post=55119"},{"taxonomy":"blog-tag","embeddable":true,"href":"https:\/\/www.sumologic.com\/ko\/wp-json\/wp\/v2\/blog-tag?post=55119"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}