Meet Constantine – Find Mythos-level vulnerabilities in your code. It proves them, patches them, PRs them back. Autonomously.

Hunt, Triage, and Act on Guard Findings in Slack

Marcus integrated in slack

Block Kit alerts, threaded conversations with Marcus, and every action tied to a verified Guard identity.

The alert that matters usually lands in Slack. Someone sees it, someone else asks what it affects, and a third person opens another tab to find out. Every context switch is time an attacker spends inside the window you are trying to close.

Worse, the integrations that bring security data into chat tend to trust whoever is typing. An email address that matches is treated as proof of identity. That is not authorization, and attackers know it.

The Guard’s Slack integration used to be a one-way webhook. Marcus replaces it with a real Slack app that delivers alerts, runs conversations in your channels, and ties every request to an authenticated Guard user.

Here’s what changed.

Install it like a Slack app, not a webhook

A Guard admin clicks Add to Slack, completes OAuth v2, picks the target channels, and the app is live. It is a multi-tenant install, so there is no webhook URL to paste into a form and nothing to rotate when someone leaves the team.

Channel management is explicit. You map specific Slack channels to your Guard tenant, and a confirmation step runs before the connection is established. You can view every connected channel with its tenant mapping on a per-row basis, and disconnect any of them through a confirmation-gated flow. Nothing quietly starts posting findings into a channel nobody meant to include.

Alerts that carry structure

Risk transitions, exposure alerts, and emergent-threat notifications now arrive as structured Block Kit messages sent through the bot token. The old webhook payloads were plain text. Structured messages are easier to scan in the middle of an incident and easier to act on, which is what you want from a notification about your own attack surface.

Talk to Marcus where the team already is

Mention Marcus in a connected channel and it runs the same queries and actions available in the Guard UI. Replies stay in a thread, so each conversation keeps its own context and a busy incident channel does not turn into a wall of interleaved answers.

Marcus is the interactive agent in the Guard, the same one referenced in our post on Hannibal and autonomous penetration testing. Putting it in Slack means a responder can ask a question about a finding without leaving the conversation about that finding.

Marcus also uses the same status labels you see in the Guard UI: Detected, Demonstrated, Resolved, Accepted, and Rejected. What you read in Slack matches what you would read in the platform.

Identity is bound, not guessed

This is the part a practitioner should care about most. Being able to query and act on your security platform from chat is only safe if the platform knows who is asking.

Matching on email alone is the approach many chat integrations use, and it is spoofable. Slack Connect guests and mutable email attributes both give an attacker room to appear as someone they are not. Marcus does not rely on it.

Instead, each Slack user runs a one-time Connect your Guard account flow that binds their Slack identity to their Guard user. After that:

  • Queries and actions execute as that Guard identity.
  • Full Guard RBAC applies, so a user in Slack can do what they could do in the UI and nothing more.
  • Every action in Slack is traceable to an authenticated Guard user.
  • Either side can revoke the link. Revoking from Guard or from Slack immediately severs the binding, and other users are unaffected.

That explicit binding is what makes it reasonable to expose the Guard’s full query and action surface through a chat interface in the first place.

Get started

Go to Integrations > Notifications > Slack (Chat Bot), then click Add to Slack and complete the OAuth flow. After authorizing, bind one or more channels to your tenant. Each team member links their Guard account once by following the in-app prompt. The Slack documentation covers the full setup.

Why this matters

Incident response runs in chat. Findings, alerts, and workflows now reach the channels your team already uses for collaboration, without a trip back to the Guard UI for every follow-up question.

The tradeoff in most chat integrations is convenience against control. Marcus does not make you choose. Notifications are structured, conversations are threaded, and every request is attributed to a verified user with their own permissions and a binding they can revoke.

The best way to see it is in your own environment. Sign up for the free Guard tier and connect Slack, or book a demo and we will walk through the install and identity linking with you.

About the Authors

Catch the Latest

Catch our latest exploits, news, articles, and events.

Ready to Discuss Your Next Continuous Threat Exposure Management Initiative?

Praetorian’s Offense Security Experts are Ready to Answer Your Questions