SlackPirate Set Sails Again! Or: How to Send the Entire “Bee Movie” Script to Your Friends in Slack
ID: 37673ac1-56b9-5af0-8009-66d7a3ff55d1
STIX ID: report--37673ac1-56b9-5af0-8009-66d7a3ff55d1
Feed Name: Security Boulevard
This post explains how Slack API changes now require an xoxc token alongside cookies and introduces a BOF that extracts both from Slack/Electron or browser process memory to enable authenticated API access. The author updates SlackPirate to support token+cookie authentication, focuses default searches on credentials and easily parsed file types, removes interactive multi-workspace mode, and expands AWS-focused functions to also detect Azure data, recommending Nemesis for automated analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
