Canarytokens
Free tripwire token service that alerts when attacker-tripped files, URLs, or credentials are used.
Technical Architecture & Overview
Canarytokens generates small tripwires such as web bugs, DNS names, Word documents, fake AWS keys, and Windows folder tokens, then fires an alert with source details when one is touched. The hosted service is free, and the server code is open source for self-hosting under a GPLv3 license with additional conditions. Tokens need no agent on the systems they watch.
Targeted Technical Use Cases
Cheap, agentless tripwires dropped into file shares, credential vaults, and cloud consoles as early-warning sensors.
Evaluation & Trade-offs
Core Strengths
- +Deployment takes minutes and costs nothing on the hosted service.
- +Token types cover file, network, and cloud scenarios.
- +Self-hosting option keeps alerting infrastructure internal.
Trade-Offs & Limitations
- -A token only fires if the attacker uses it.
- -Alerts can be delayed for token types that depend on DNS propagation.
Defensive Security Application
Early intrusion detection through planted artifacts that legitimate activity should never touch.
Frequently Asked Questions
What is Canarytokens?→
Canarytokens generates small tripwires such as web bugs, DNS names, Word documents, fake AWS keys, and Windows folder tokens, then fires an alert with source details when one is touched. The hosted service is free, and the server code is open source for self-hosting under a GPLv3 license with additional conditions. Tokens need no agent on the systems they watch.
What is Canarytokens used for?→
Cheap, agentless tripwires dropped into file shares, credential vaults, and cloud consoles as early-warning sensors.
What are the strengths of Canarytokens?→
- +Deployment takes minutes and costs nothing on the hosted service.
- +Token types cover file, network, and cloud scenarios.
- +Self-hosting option keeps alerting infrastructure internal.
What are the limitations of Canarytokens?→
- +A token only fires if the attacker uses it.
- +Alerts can be delayed for token types that depend on DNS propagation.
How is Canarytokens used defensively?→
Early intrusion detection through planted artifacts that legitimate activity should never touch.