Discord third-party & OAuth apps security checks
OAuth grants, marketplace apps, integrations, plugins and automations with standing access to company data — the SaaS-to-SaaS supply chain.
On Discord, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Discord connector needs.
Checks (4)
severity: medium Excessive Integrations fix difficulty: medium #
Review and remove unused integrations to reduce third-party risk
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Integrations" in the left panel
- Review the list of webhooks and bots; identify unused or unrecognized integrations
- Delete integrations that are no longer needed by clicking the entry and selecting "Delete"
- Aim to keep active integrations below 25
Satisfies: ISO 27001:2022 A.5.23 CIS Controls v8 CIS-15.1 NIST CSF 2.0 GV.SC GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: info Webhook Inventory fix difficulty: easy #
Review each webhook to confirm it is still needed and properly governed
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Integrations" in the left panel
- Click "Webhooks" to view all webhooks in the server
- For each webhook, verify its name, channel assignment, and owning application
- Delete webhooks that are no longer in use or cannot be attributed to a known integration
Satisfies: ISO 27001:2022 A.5.23 CIS Controls v8 CIS-15.1 NIST CSF 2.0 GV.SC GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: medium Orphaned Webhook fix difficulty: easy #
Delete webhooks whose creator has left the server or that have no known owner
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Integrations" > "Webhooks" in the left panel
- Identify webhooks created by users no longer in the server
- Click the webhook and select "Delete Webhook"
- Recreate the webhook under an active service account or bot if the integration is still needed
Satisfies: ISO 27001:2022 A.5.23 CIS Controls v8 CIS-15.1 NIST CSF 2.0 GV.SC GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: high Bot With Admin fix difficulty: medium #
Remove Administrator permission from bot roles and grant only the permissions each bot requires
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Roles" in the left panel
- Locate the role assigned to the flagged bot
- Disable the "Administrator" permission and enable only the specific permissions the bot needs
- Save the changes and verify the bot still functions as expected
Satisfies: ISO 27001:2022 A.5.23 CIS Controls v8 CIS-15.1 NIST CSF 2.0 GV.SC GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4