Deploy Dune Guardian for Slack
Access real-time notifications, collaboration through ChatOps, and automation to keep your team informed and secure.
Dune Guardian is a powerful extension of the Dune platform, designed to enhance user experience and streamline security management directly within your organization's Slack workspace.
Primary Functions and Capabilities
- Integration with Slack: Dune Guardian seamlessly integrates with Slack, bringing many of Dune's actionable insights directly to your Slack workspace.
- Real-Time Notifications: Provides immediate updates on phishing alerts, training reminders, and security tips.
- ChatOps Ecosystem: Facilitates collaboration and automation within Slack, making security management more efficient and interactive.
Types of Notifications
-
Phishing Alerts
- Audience: Sent exclusively to admins to notify them in real-time when a user falls for a phishing attempt.
- Content: Includes details such as the affected user’s email, the subdomain involved, and the timestamp of the incident. It also specifies if the user submitted their password.
-
Training Reminders
- Audience: Employees
- Content: Regular reminders to users to complete security training, ensuring they stay compliant with security protocols.
-
Security Tips
- Audience: Employees
- Content: Periodic tips aimed at improving users' security awareness and practices.
Notification Cadence
-
Training Tips and Reminders
- Default Schedule: Notifications are typically sent between 8 AM - 12 PM EST on Thursdays.
- Customization: Admins can adjust this schedule using a cron schedule to better fit organizational needs.
-
Phishing Notifications
- Asynchronous: These are sent out in real-time when a phishing incident is detected, ensuring immediate admin awareness.
Configuring Notifications
- Control Over Notification Cadence
- Training Notifications: Users can customize how often and when training notifications and tips are received.
- Recipient Management
- Phishing Alerts: Only admins receive phishing alerts to ensure prompt and targeted responses to security incidents.
Messaging and Verbiage
Dune Guardian uses engaging and motivational language to encourage user participation in security training and awareness activities. The messaging is designed to be friendly, yet persistent, reinforcing the importance of cybersecurity in a positive and action-oriented manner. Here’s a breakdown of the messaging style:
Training Reminders
- Sent to: Employees
- Tone: Encouraging, Positive, and Supportive.
- Examples:
- "Hello [User], explore your security training and learn the fundamentals of online safety. 🔐 [Login]"
- "Get set, [User]! Complete your security training to stay proactive against cyber threats. 🚀 [Login]"
- "Your progress in security training is vital, [User]. Your expertise benefits us all. 🏅 [Login]"
- "Time to expand your knowledge, [User]! Let's fill your mind with vital security insights. 🎉 [Login]"
Security Tips
- Sent to: Employees
- Tone: Informative, Motivational.
- Examples:
- "🔒 Security Tip: Always use multi-factor authentication (MFA) to add an extra layer of security to your accounts."
- "📧 Security Tip: Be cautious of unexpected email attachments or links—phishing attempts often hide in plain sight."
- "🔍 Security Tip: Regularly update your software to patch security vulnerabilities and keep your systems secure."
- "🛡️ Security Tip: Use strong, unique passwords for different accounts to reduce the risk of a security breach."
Phishing Alerts
- Sent to: Admins
- Tone: Urgent, Direct.
- Example:
- "User [email] just got phished by [subdomain]. Outgoing Timestamp: [timestamp]. User [email] submitted their password! 🆔"
General Messaging Tips
- Frequency: Messages are sent regularly to ensure that users are consistently reminded of their training responsibilities without feeling overwhelmed.
- Customization: While the messages are pre-set, they are customizable to align with the tone and culture of your organization.
- Future Updates: Planned enhancements include AI-based insights and recommendations targeted at CISOs, and notifications related to training completion and compliance.
Admin Interface and Management
-
Slack Slash Commands
- Current Management: Admins manage notifications and settings through slash commands within the Slack environment. This allows for quick adjustments and control over the notification system.
-
Future Enhancements
- Slack Card UI Elements: Planned improvements will include a more intuitive UI within Slack, utilizing Slack Cards to make management easier and more visual.
Future Notifications
-
Training Completion or Compliance Notifications
- Purpose: To keep track of user compliance and training progress, ensuring all users meet security standards.
-
AI-Based Insights and Recommendations
- Target: Primarily for CISOs, these insights will provide actionable intelligence based on the latest cybersecurity trends and internal data analysis.
-
Current Events and Cybersecurity Trends
- Webhooks: Real-time updates and aggregated data from third-party sources, keeping the organization informed about the latest cybersecurity news and trends.
Dune Guardian is a flexible, powerful tool designed to keep your organization secure while integrating seamlessly with your daily workflows in Slack. With real-time notifications, customizable settings, and a roadmap of future enhancements, Dune Guardian is an essential part of your security infrastructure.
Stay tuned for upcoming features that will further enhance its capabilities and ease of use.