Canarytokens logo

Canarytokens

Website

Honeytokens that alert when accessed or executed

3k stars 410 forks last commit first released BSD-3-Clause

Actively maintained

Last commit 13 Aug 2026.

Canarytokens screenshot

Canarytokens is a honeytoken service that lets you create “tripwires” (tokens) and place them in files, documents, credentials, and network locations to detect unauthorized access. When a token is triggered, it generates an alert so you can investigate potential compromise quickly.

Key Features

  • Generates multiple token types (for example: web/URL tokens, documents, credentials, and other bait artifacts)
  • Immediate alerting when a token is accessed, opened, or executed
  • Simple token management for creating, naming, and tracking deployed tokens
  • Designed to work as a lightweight breach-detection layer alongside existing security controls

Use Cases

  • Detect unauthorized access to internal file shares, documentation, or secrets
  • Place decoy links or documents to identify phishing or lateral movement
  • Monitor for misuse of planted credentials or high-value data locations

Limitations and Considerations

  • Tokens provide detection and investigation signals, not prevention or containment
  • Effectiveness depends on careful placement and operational follow-up when alerts trigger

Canarytokens is useful as a low-friction way to add early breach detection across common attacker touchpoints. It complements traditional monitoring by turning sensitive locations and decoy assets into actionable security alerts.

Categories:

Tags:

Tech Stack:

Share:

Similar to Canarytokens

CrowdSec logo

CrowdSec

Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence

14.7k
710
Last commit

CrowdSec is an open-source security engine that detects attacks from logs and blocks malicious IPs using bouncers and community-curated threat intelligence.

MITActively maintained
Alternative to:
Fail2Ban logo
Fail2Ban
+10
OneUptime logo

OneUptime

Open-source monitoring, incident management, and observability platform

7.5k
445
Last commit

Self-hostable observability platform for uptime monitoring, alerting, incident management, on-call, status pages, logs, and APM in one integrated suite.

Apache-2.0Actively maintained
Alternative to:
OneUptime logo
OneUptime
+19
Beelzebub logo

Beelzebub

Low-code honeypot framework using LLMs for safe system deception

2.2k
206
Last commit

Secure low-code honeypot framework that uses LLMs to simulate high-interaction systems across SSH/HTTP/TCP and MCP, with metrics and cloud-native deployment options.

GPL-3.0Actively maintained
Alternative to:
Thinkst Canary logo
Thinkst Canary
+1

NetAlertX

Network device scanner and presence detection with alerts

7k
426
Last commit

Self-hosted network visibility and presence scanner that discovers connected devices and alerts on new, unknown, or changed hosts across your LAN/Wi‑Fi.

GPL-3.0Actively maintained
Alternative to:
Fing logo
Fing
+8
Tracearr logo

Tracearr

Real-time monitoring and analytics for Plex, Jellyfin, and Emby

2.5k
79
Last commit

Real-time monitoring platform for Plex, Jellyfin, and Emby with session tracking, playback analytics, stream maps, alerts, and account-sharing detection rules.

AGPL-3.0Actively maintained
Alternative to:
Tautulli logo
Tautulli
+1
GlobaLeaks logo

GlobaLeaks

Secure whistleblowing and anonymous reporting platform

1.5k
355
Last commit

Open-source platform for secure, anonymous whistleblowing and case handling, designed for privacy by default and adaptable to many reporting use cases.

AGPL-3.0Actively maintained