Canarytokens

Canarytokens

Honeytokens that alert when accessed or executed

2.7kstars
393forks
Last commit: 5d ago
Repo age: 11y old
Canarytokens screenshot

Canarytokens is a honeytoken service that lets you create “tripwires” (tokens) and place them in files, documents, credentials, and network locations to detect unauthorized access. When a token is triggered, it generates an alert so you can investigate potential compromise quickly.

Key Features

  • Generates multiple token types (for example: web/URL tokens, documents, credentials, and other bait artifacts)
  • Immediate alerting when a token is accessed, opened, or executed
  • Simple token management for creating, naming, and tracking deployed tokens
  • Designed to work as a lightweight breach-detection layer alongside existing security controls

Use Cases

  • Detect unauthorized access to internal file shares, documentation, or secrets
  • Place decoy links or documents to identify phishing or lateral movement
  • Monitor for misuse of planted credentials or high-value data locations

Limitations and Considerations

  • Tokens provide detection and investigation signals, not prevention or containment
  • Effectiveness depends on careful placement and operational follow-up when alerts trigger

Canarytokens is useful as a low-friction way to add early breach detection across common attacker touchpoints. It complements traditional monitoring by turning sensitive locations and decoy assets into actionable security alerts.

Categories:

Tags:

Tech Stack:

Share:

Similar Services

Web-Check

Web-Check

All-in-one OSINT tool for analyzing any website.

30k
2.4k
Last commit: 4d ago

Comprehensive on-demand OSINT to analyze a website's security, architecture, and tech stack.

Alternative to:
Shodan
Shodan
+8
SafeLine

SafeLine

Self-hosted WAF and reverse proxy for securing web apps

20.1k
1.3k
Last commit: 2mo ago

SafeLine is a self-hosted Web Application Firewall (WAF) and reverse proxy that defends web apps from SQL injection, XSS, bot abuse, and DDoS using ML-powered threat dete...

Alternative to:
Cloudflare Web Application Firewall (WAF)
Cloudflare Web Application Firewall (WAF)
+7
Fail2Ban

Fail2Ban

Log-monitoring daemon that bans abusive IPs via firewall rules

16.6k
1.4k
Last commit: 15d ago

Fail2Ban monitors service logs for repeated failures and automatically bans abusive IP addresses by updating firewall rules for a configurable time.

Alternative to:
CrowdSec
CrowdSec
CrowdSec

CrowdSec

Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence

12.2k
567
Last commit: 18h ago

CrowdSec is an open-source security engine that detects attacks from logs and blocks malicious IPs using bouncers and community-curated threat intelligence.

Alternative to:
Fail2Ban
Fail2Ban
+10
Graylog

Graylog

Centralized log management and analysis platform

7.9k
1.1k
Last commit: 1d ago

Graylog is an open source platform for collecting, indexing, searching, and alerting on logs and machine data from many sources in one place.

Alternative to:
Graylog Cloud
Graylog Cloud
+11
OneUptime

OneUptime

Open-source monitoring, incident management, and observability platform

6.4k
307
Last commit: 20h ago

Self-hostable observability platform for uptime monitoring, alerting, incident management, on-call, status pages, logs, and APM in one integrated suite.

Alternative to:
OneUptime
OneUptime
+19