Skip to main content

Cyware Fusion and Threat Response

Integrate Slack

Integrate Slack with CFTR to receive incident update notifications on a Slack channel. This helps non-CFTR users to be notified of the progress of important incidents. Configure your Slack workspace and channel to receive notifications.

Before you Start

Before you integrate Slack with CFTR, ensure that:

  • Orchestrate is integrated and enabled in CFTR. For more information, see Integrate Orchestrate.

  • You have Create/Update permission to Configurations.

Steps

Install Slack on Orchestrate

To install the Slack app on Orchestrate, do the following:

  1. Sign in to Orchestrate.

  2. Go to Main Menu > Apps and select the Appstore tab.

  3. Search and open the Slack app.

  4. Click Install on the top-right.

  5. Select a version and click Install.

The Slack app is installed on Orchestrate and you can find the app under the My Apps tab.

Create Slack Instance

Create a Slack instance to enable communication between Orchestrate and Slack using APIs. 

Note

Ensure that you have a valid Slack integration API token with channels:read, chat:write, and users:read.mail permissions.

To create a Slack instance in CFTR, do the following:

  1. Go to Admin Panel > Configurations > Integrations > Orchestrate Integration.

  2. Go to Slack, click Edit.

  3. Under Select Instance, click +New Instance.

  4. Enter the following details:

    • Instance name: Enter a name for the instance.

    • Instance Description: Enter a description for the instance.

    • Instance Expiration: Enter the expiration date of the instance.

    • Slack Token: Enter the Slack integration API token.

    • App Version: Enter the version of your Slack app.

  5. Click Create.

Configure Slack Channel in CFTR

To integrate Slack and configure a Slack channel to receive incident update notifications, do the following:

  1. Go to Admin Panel > Configurations > Integrations > Orchestrate Integration.

  2. Go to Slack and click Edit.

  3. Enter the following details:

    1. Instance: Select an instance of your Slack workspace.

    2. Channel: Select a Slack channel on which you want to receive incident update notifications.

  4. Click Save.