discovered 03 Aug 2026
EvilSlackbot
→ View on GitHubEvilSlackbot is a specialized framework designed for Red Team and phishing exercises within Slack workspaces, enabling security professionals to automate attacks such as sending spoofed messages, phishing links, and file attachments. It allows users to leverage exposed Slack API tokens to efficiently conduct various types of assessments, including searching for leaked secrets and simulating phishing scenarios. Notable features include customizable spoofing capabilities, an ability to analyze token permissions, and functionalities to send malicious attachments or messages to targeted users or channels.