By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Slack Security: Inside the New Anomaly Event Response Architecture
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Slack Security: Inside the New Anomaly Event Response Architecture
News

Slack Security: Inside the New Anomaly Event Response Architecture

News Room
Last updated: 2025/10/17 at 10:10 AM
News Room Published 17 October 2025
Share
Slack Security: Inside the New Anomaly Event Response Architecture
SHARE

Slack has launched a new security system called Anomaly Event Response (AER) to detect and respond to suspicious activity in real time. The system is designed to reduce the time between detection and mitigation, helping organizations prevent potential security breaches before they escalate.

AER is a native security feature that autonomously identifies high-confidence threat actor behaviors on the Slack platform. When suspicious activity is detected, the system can automatically terminate the associated user sessions, reducing the security detection and response gap from potential days or hours to minutes.

Slack engineers Nathan Lehotsky and Ryan Persaud emphasized the company’s approach to security:

 Trust is our number one core value. We believe security is a shared responsibility between us and our customers by empowering them with data and tools to build security solutions while also fostering a secure platform and neutralizing threats.

The architecture of Anomaly Event Response consists of three main components: a detection engine, a decision framework, and a response orchestrator. The detection engine continuously monitors billions of Slack events daily, applying rule-based heuristics and dynamic thresholds tailored to each organization’s usage patterns. It identifies unusual activities such as logins from Tor exit nodes, rapid file downloads, excessive API calls, session fingerprint mismatches, and non-standard user agents.

Slack AER System Architecture (Source: Slack Engineering Blog Post)

When a potential threat is detected, the decision framework validates the anomaly against internal rules and the organization’s configuration. This step reduces false positives and ensures that only genuine threats trigger automated actions. The response orchestrator then executes pre-defined actions, including terminating affected sessions, generating audit logs, and notifying relevant security teams. Notification logic ensures alerts are not duplicated for users holding multiple roles, keeping incident response manageable.

Slack provides comprehensive audit logs to Enterprise customers, recording when entities take actions on the platform. AER extends this with anomaly audit logs, which automatically link detected anomalies to responses. While full integration into broader security solutions may not be feasible for all organizations, AER offers an out-of-the-box solution for Enterprise Grid customers, usable independently or as part of a larger security strategy.

According to Slack engineers, the system is configurable, allowing organizations to determine which types of anomalies trigger need automated responses and which are only logged. Audit logs maintain a complete history of each detected anomaly and the corresponding automated response, helping organizations investigate incidents, verify actions, and maintain compliance with internal policies or regulatory requirements.

As per the Slack engineering team, AER’s approach reduces the need for manual intervention, improves transparency, and ensures that security actions are fully auditable. By bridging detection and automated response, the system allows security teams to focus on higher-priority investigations while routine anomalies are handled efficiently.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article 7 of the hottest watches launched this week | Stuff 7 of the hottest watches launched this week | Stuff
Next Article The TechBeat: Sia Foundation’s Nonprofit Cloud Model Redefines Data Ownership and Privacy (10/17/2025) | HackerNoon The TechBeat: Sia Foundation’s Nonprofit Cloud Model Redefines Data Ownership and Privacy (10/17/2025) | HackerNoon
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

UK businesses are falling behind on AI strategy, research finds – UKTN
UK businesses are falling behind on AI strategy, research finds – UKTN
News
AWS introduces Nova Forge for training bespoke ‘Novella’ frontier models –  News
AWS introduces Nova Forge for training bespoke ‘Novella’ frontier models – News
News
Anker’s new desktop docking station has a removable USB-C hub you can take with you
Anker’s new desktop docking station has a removable USB-C hub you can take with you
News
The HackerNoon Newsletter: How Will We Distinguish Truth From Fiction? (12/2/2025) | HackerNoon
The HackerNoon Newsletter: How Will We Distinguish Truth From Fiction? (12/2/2025) | HackerNoon
Computing

You Might also Like

UK businesses are falling behind on AI strategy, research finds – UKTN
News

UK businesses are falling behind on AI strategy, research finds – UKTN

2 Min Read
AWS introduces Nova Forge for training bespoke ‘Novella’ frontier models –  News
News

AWS introduces Nova Forge for training bespoke ‘Novella’ frontier models – News

5 Min Read
Anker’s new desktop docking station has a removable USB-C hub you can take with you
News

Anker’s new desktop docking station has a removable USB-C hub you can take with you

3 Min Read
HP FilmScan 5-Inch Touch Screen Film Scanner: Serviceable Slide and Filmstrip Digitizing on a Budget
News

HP FilmScan 5-Inch Touch Screen Film Scanner: Serviceable Slide and Filmstrip Digitizing on a Budget

8 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?