#CanaryTokens

Claus Cramon Houmannclaushoumann
2024-10-24

And as the final presenter before lunch on day 3, @Jacob is now on stage talking about protecting against attacks at scale with - at @hack_lu !!

2023-11-11

Can somebody point out what I am obviously missing?
In this guide on #canarytokens

docs.canarytokens.org/guide/dn
it is explained howto make a dns token. Fine, I get how a resolution of a dns something produces a warning.

But then they state: leave in_bash-history or ssh/config or servers.txt

But how do you adding such a token in your bash history lead to a tripwire?
Should you than add something like
ssh root@tokenurl or something?

and than hope the hacker tries this? Or what would you do?
#blueteam
#infosec

2023-08-23

Tourists Give Themselves Away by Looking Up. So Do Most Network Intruders. - In large metropolitan areas, tourists are often easy to spot because they’re far m... krebsonsecurity.com/2023/08/to #thecomingstorm #securitytools #canarytokens #hazelburton #shubhamshah #ransomware #ciscotalos #haroonmeer #assetnote #thinkst

2023-02-13
Excited to see the open-source canarytokens.org offering #Azure #CanaryTokens! One more type of sensitive data that attackers now need to worry about using: https://blog.thinkst.com/2023/02/canarytokens-org-welcomes-azure-login-certificate-token.html
Marius (windsheep) 📡​ 🦃​ :CIAverified:​ :donor:​windsheep@infosec.exchange
2023-01-19

Looking for an DBMS-way to implement #canarytokens with a #MongoDB that sends a pingback if a certain row is queried. Research...
canarytokens.org/generate

Today is a good day to add canary tokens to your infrastructure!



Did you know you can get free #CanaryTokens from @ThinkstCanary to alert on suspicious activity?

On canarytokens.org/generate, you can generate a whole range of “canaries”, or assets that look like one thing but will actually email you as soon as someone or something interacts with them.



A canary can be a pdf file called “password.pdf”, left on server, a computer or attached to an email. 



A canary can be AWS keys, left in a config file or committed in a private git repo.

A canary can listen for SQL commands or command being run.

A canary can be an email address, included in customer or employee lists.

They are traps you place, so you know something’s been compromised and your team can start investigating immediately *.

Check out the documentation for more examples and use cases: docs.canarytokens.org/guide/

Set up your free #HoneyPots this month! #NewYearResolutions



* These are free so there are some limitations, but still super neat to have.

d0pp3l6ang3r :verified: :donor:d0pp3l6ang3r@infosec.exchange
2023-01-06

Now is a good time for you to drop couple of #AWS #canarytokens in your #slack chats. You might get lucky...
#detectionengineering #spotthebirdie

Patryk Krawaczyńskiagresor@infosec.exchange
2022-11-12

Kanarek rozdaje tokeny, czyli jak używać Canarytokens ( nfsec.pl/security/5883 ) #canarytokens #honeytokens #honeypot #ids #url #file #twittermigration

d0pp3l6ang3r :verified: :donor:d0pp3l6ang3r@infosec.exchange
2022-11-06

#BlueTeamtoot of the day: Search for AKIA*, ASIA* and ABIA* in your slack/teams/jira/confluence etc, you might be surprised. #Redteams do the same, you might get lucky 😅
#DetectionEngineering teams drop some #AWS API key #CanaryTokens in your chatops tooling, when it triggers an alert you know you have a problem

Intrusion Alert: Michael Hill explains how GitGuardian's #OpenSource canary tokens can help detect compromised DevOps environments fosslife.org/open-source-canar #ggcanary #GitHub #GitGuardian #CanaryTokens #AWS #DevOps #security

brass digital padlock with blue chip background
2022-01-04

Detect Vulnerable Log4J Websites with CanaryTokens

On this episode of HakByte, Alex Lynd demonstrates how to test if web applications are vulnerable to the Log4Shell exploit, using CanaryTokens.

#HakByte #Log4J #Log4Shell #CanaryTokens

youtube.com/watch?v=qjA_vc9Ua5

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst