Skip to main content

Slack legal hold policy modified

ID:slack_legal_hold_policy_modified
Data type:Slack
Severity:
Low
MITRE ATT&CK:TA0005:T1562.001

Description

AlphaSOC detected changes to Slack legal hold policies. Legal hold policies preserve messages and files from given members in Slack Enterprise Grid organizations. These policies override standard retention settings and prevent deletion or modification of content under hold.

Impact

Modifying legal hold policies can disrupt evidence preservation, potentially violating legal requirements and compliance obligations. Threat actors may alter these settings to destroy evidence of their activities or to prevent proper forensic investigation.

Severity

SeverityCondition
Low
Slack legal hold policy modified

Investigation and Remediation

Review Slack audit logs to determine the identity of users who modified legal hold policies. Confirm whether these changes were authorized and properly documented through change management processes. Assess the scope of impact by examining affected users and channels. If unauthorized changes occurred, restore the previous legal hold settings immediately. Review Legal Holds Admin role assignments and implement stricter access controls if necessary. Document all findings and notify relevant stakeholders including legal and compliance teams.