{"repo":"PaperMtn/slack-watchman","free":true,"listed":false,"github":"https://github.com/PaperMtn/slack-watchman","clone":"git clone https://github.com/PaperMtn/slack-watchman.git","description":"Slack enumeration and exposed secrets detection tool","language":"Python","stars":403,"topics":["blueteam","blue-team","cybersecurity","infosec","slack","tools","redteam","red-team","purpleteam","purple-team"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":"Slack Watchman Monitoring and enumerating Slack for exposed secrets About Slack Watchman Slack Watchman is an application that uses the Slack API to find potentially sensitive data exposed in a Slack workspace, and to enumerate other useful information for red, blue and purple teams. More information about Slack Watchman can be found on my blog. Features Secrets Detection Slack Watchman looks for: - API Keys, Tokens & Service Accounts - AWS, Azure, GCP, Google API, Slack (keys & webhooks), Twitter, Facebook, GitHub and more - Generic Private keys - Access Tokens, Bearer Tokens, Client Secrets, Private Tokens - Files - Certificate files - Potentially interesting/malicious/sensitive files (.docm, .xlsm, .zip etc.) - Executable files - Keychain files - Config files for popular services (Terraform, Jenkins, OpenVPN and more) - Personal Data - Leaked passwords - Passport numbers, Dates of birth, Social security numbers, National insurance numbers and more - Financial data - Paypal Braintree tokens, Bank card details, IBAN numbers, CUSIP numbers and more Time based searching You can run Slack Watchman to look for results going back as far as: - 24 hours - 7 days - 30 days - All time Enumeration It also enumerates the following: - User data - All users & all admins - Conversation data - All conversations, including externally shared conversations - All conversations that include a Slack Canvas (which often contain sensitive or important information) - Workspace authentication option","default_branch":null,"files":null,"tree":[],"storefront":"/r/PaperMtn","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/PaperMtn/slack-watchman/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}