CloudSOC Slack Securlet: Quarantine Remediation Failures Due to Bot Configuration or Manual Channel Creation
search cancel

CloudSOC Slack Securlet: Quarantine Remediation Failures Due to Bot Configuration or Manual Channel Creation

book

Article ID: 444131

calendar_today

Updated On:

Products

CASB Securlet SAAS CASB Advanced Threat Protection CASB Security Advanced CASB Security Advanced IAAS CASB Security Premium CASB Security Standard

Issue/Introduction

In a Broadcom CloudSOC (CASB) environment utilizing the Slack Securlet, administrators may observe partial or total failures when attempting to perform remediation actions, specifically quarantine operations. Files or messages flagged for quarantine are not successfully moved from their original location to the designated quarantine area.

Environment

  • Broadcom CloudSOC (CASB)
  • Slack Securlet (API Integration)

Cause

The quarantine functionality within the Slack Securlet is strictly tied to the Slack Securlet Bot. Failures typically occur due to one of the following conditions:

  • Bot Parameter Changes: The Bot has been disabled in the Slack workspace, or its necessary permissions have been modified/revoked.
  • Missing Channel Dependency: The quarantine channel is missing, and the Bot is currently disabled, preventing it from automatically recreating the required location.
  • Manual Channel Creation: An administrator manually created the quarantine channel. The Securlet Bot must be the owner of the channel to accurately perform its functions (moving files/messages). If created manually, the Bot lacks the necessary ownership context, leading to remediation failures.

Resolution

To restore quarantine functionality, ensure the Slack Securlet Bot is healthy and managing the channel autonomously. Follow these steps:

  1. Verify that the Slack Securlet Bot is enabled and active within the Slack workspace.
  2. Ensure the Bot's permissions have not been restricted or modified from the original Broadcom CloudSOC installation requirements.
  3. Do not manually create the quarantine channel. If a quarantine channel was recently created manually by an administrator, rename or delete it.
  4. Allow the Slack Securlet Bot to autonomously check for the existence of the quarantine channel. If the channel is missing, the Bot is designed to automatically recreate it, ensuring it retains the exact ownership and permissions required to execute remediation actions.

Additional Information

Marking vs. Moving Content: It is important to distinguish between marking an item as quarantined and physically moving it. CloudSOC can mark content as "quarantined" within Slack without depending on the Bot. When marked, the content becomes completely hidden from the end user (they cannot view or access it), even though it technically remains in its original location. However, the action of actually moving the contents off their original location to the designated quarantine channel strictly requires an active, properly configured Bot.

Securlet Reactivation & Slack Policies: Typically, the Securlet will attempt to automatically enable the Bot during a reactivation. However, there are cases where this automated step fails because Slack configurations or bot management policies cannot be overridden if they are strictly enforced by the Slack Organiz