In a Broadcom CloudSOC (CASB) environment utilizing the Slack Securlet, administrators may observe partial or total failures when attempting to perform remediation actions, specifically quarantine operations. Files or messages flagged for quarantine are not successfully moved from their original location to the designated quarantine area.
The quarantine functionality within the Slack Securlet is strictly tied to the Slack Securlet Bot. Failures typically occur due to one of the following conditions:
To restore quarantine functionality, ensure the Slack Securlet Bot is healthy and managing the channel autonomously. Follow these steps:
Marking vs. Moving Content: It is important to distinguish between marking an item as quarantined and physically moving it. CloudSOC can mark content as "quarantined" within Slack without depending on the Bot. When marked, the content becomes completely hidden from the end user (they cannot view or access it), even though it technically remains in its original location. However, the action of actually moving the contents off their original location to the designated quarantine channel strictly requires an active, properly configured Bot.
Securlet Reactivation & Slack Policies: Typically, the Securlet will attempt to automatically enable the Bot during a reactivation. However, there are cases where this automated step fails because Slack configurations or bot management policies cannot be overridden if they are strictly enforced by the Slack Organiz