Flag risky IP reports in Slack
Give incoming IP reports a quick reputation check and a visible signal in the Slack message they came from.
Trigger
Webhook received
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Action
Add reaction to message
Adds a specified emoji reaction to an existing message in a slack channel, identified by its timestamp; does not remove or retrieve reactions.
Why this helps
Suspicious IPs can get buried in busy Slack conversations before anyone checks their reputation.
- Surface concerning IP reports where the team already discusses them.
- Reduce manual copy and paste between threat checks and Slack.
- Keep a human review step for interpreting reputation results.
Setup
Build it in a few focused steps.
- 1Connect Abuselpdb and Slack once in the Notis portal.
- 2Create an automation and describe the IP check and reaction outcome in one instruction.
- 3Choose the Notis webhook trigger and send the IP plus the Slack channel and message timestamp in its request.
- 4Choose where run reports go, then test with one real report and verify the reaction.
Questions about this workflow
What information must the webhook include?
Include the IP address and the Slack channel and message timestamp for the report to react to. Notis needs those message details to identify the Slack message.
Will every checked IP get a reaction?
Set the instruction to react only when the Abuselpdb result meets your stated review criteria. The reputation threshold should be supplied in your instruction.
Does this automatically report an IP as abusive?
No. This workflow checks reputation and reacts to the Slack message. It does not submit an abuse report.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Abuselpdb to Slack. A trigger fires from one place; an action lands in another.
Abuselpdb triggers
Slack actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Set snooze duration
Deprecated: turns on do not disturb mode for the current user, or changes its duration. use `set dnd duration` instead.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Add a custom emoji to a Slack team
Deprecated: adds a custom emoji to a slack workspace given a unique name and an image url. use `add emoji` instead.
Add an emoji alias
Adds an alias for an existing custom emoji in a slack enterprise grid organization.
Add a remote file
Adds a reference to an external file (e.g., google drive, dropbox) to slack for discovery and sharing, requiring a unique `external id` and an `external url` accessible by slack.
Add a star to an item
Stars a channel, file, file comment, or a specific message in slack.
Add call participants
Registers new participants added to a slack call.
Add emoji
Adds a custom emoji to a slack workspace given a unique name and an image url; subject to workspace emoji limits.
Add reaction to message
Adds a specified emoji reaction to an existing message in a slack channel, identified by its timestamp; does not remove or retrieve reactions.
Connect any two apps with Notis in the middle.
Abuselpdb and Slack, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Slack.