💬
Slack Integration
Connect Slack to Ayzal AI SOC to create security alerts from Slack messages and commands.
⚙️ How It Works
- Team members can report security incidents via Slack slash commands
- Alerts are automatically forwarded to Ayzal AI SOC
- AI analyzes the message content for threat indicators
- Auto-remediation can be triggered for critical alerts
🚀 Setup (5 minutes)
Step 1: Create a Slack App
- Go to https://api.slack.com/apps
- Click Create New App → From Scratch
- Name: Ayzal SOC Alerts
- Select your workspace
Step 2: Add a Slash Command
- Go to Slash Commands → Create New Command
- Configure:
Command: /soc-alertRequest URL: https://api.ayzalai.com/api/integrations/slackShort Description: Report a security incident to Ayzal AI SOCUsage Hint: [severity] [description]
Step 3: Configure Request Headers
In the Slack app settings, the webhook will send these headers with each request:
x-api-key: YOUR_API_KEY
x-siem-type: slack
Step 4: Install the App
Click Install to Workspace and authorize the app.
📝 Usage Examples
/soc-alert HIGH Suspicious login from 203.0.113.42 on production server
/soc-alert CRITICAL Ransomware detected on workstation-45
/soc-alert MEDIUM Unusual outbound traffic to unknown IP
📊 Severity Mapping
The slash command parses the first word as severity:
| Slack Command | Ayzal AI SOC Severity |
|---|---|
| CRITICAL | CRITICAL |
| HIGH | HIGH |
| MEDIUM | MEDIUM |
| LOW | LOW |
💡 Pro Tip
You can add a quick action button to the slash command response for one-click ticket creation in ServiceNow or Jira.