Canarytokens
Honeytokens that alert when accessed or executed
3k stars 410 forks last commit first released BSD-3-Clause
Actively maintained
Last commit 13 Aug 2026.

Canarytokens is a honeytoken service that lets you create “tripwires” (tokens) and place them in files, documents, credentials, and network locations to detect unauthorized access. When a token is triggered, it generates an alert so you can investigate potential compromise quickly.
Key Features
- Generates multiple token types (for example: web/URL tokens, documents, credentials, and other bait artifacts)
- Immediate alerting when a token is accessed, opened, or executed
- Simple token management for creating, naming, and tracking deployed tokens
- Designed to work as a lightweight breach-detection layer alongside existing security controls
Use Cases
- Detect unauthorized access to internal file shares, documentation, or secrets
- Place decoy links or documents to identify phishing or lateral movement
- Monitor for misuse of planted credentials or high-value data locations
Limitations and Considerations
- Tokens provide detection and investigation signals, not prevention or containment
- Effectiveness depends on careful placement and operational follow-up when alerts trigger
Canarytokens is useful as a low-friction way to add early breach detection across common attacker touchpoints. It complements traditional monitoring by turning sensitive locations and decoy assets into actionable security alerts.
Categories:
Tags:
Tech Stack:
Similar to Canarytokens
CrowdSec
Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence
CrowdSec is an open-source security engine that detects attacks from logs and blocks malicious IPs using bouncers and community-curated threat intelligence.

OneUptime
Open-source monitoring, incident management, and observability platform
Self-hostable observability platform for uptime monitoring, alerting, incident management, on-call, status pages, logs, and APM in one integrated suite.

Beelzebub
Low-code honeypot framework using LLMs for safe system deception
Secure low-code honeypot framework that uses LLMs to simulate high-interaction systems across SSH/HTTP/TCP and MCP, with metrics and cloud-native deployment options.
NetAlertX
Network device scanner and presence detection with alerts
Self-hosted network visibility and presence scanner that discovers connected devices and alerts on new, unknown, or changed hosts across your LAN/Wi‑Fi.


Tracearr
Real-time monitoring and analytics for Plex, Jellyfin, and Emby
Real-time monitoring platform for Plex, Jellyfin, and Emby with session tracking, playback analytics, stream maps, alerts, and account-sharing detection rules.

GlobaLeaks
Secure whistleblowing and anonymous reporting platform
Open-source platform for secure, anonymous whistleblowing and case handling, designed for privacy by default and adaptable to many reporting use cases.



