Skip to main content

Slack - General Failed Logins v2.1

This Playbook is part of the Slack Pack.#

Investigates a failed login event. The playbook interacts with the user via the Slack integration, checks whether the logins were a result of the user's attempts or an attack, raises the severity, and expires the user's password according to the user's replies.


This playbook uses the following sub-playbooks, integrations, and scripts.


This playbook does not use any sub-playbooks.


  • Builtin


This playbook does not use any scripts.


  • setIncident
  • closeInvestigation
  • ad-expire-password
  • send-notification

Playbook Inputs#

NameDescriptionDefault ValueSourceRequired
UsernameOrEmailThe username or the email address of the user who failed to login.srcuserincidentRequired

Playbook Outputs#

There are no outputs for this playbook.

Playbook Image#

Slack - General Failed Logins V2.1