C

Canary Tokens

A free, open-source honeypot tool that deploys fake credentials, URLs, and files to detect intruders in your network.

About Canary Tokens

Canary Tokens is a deception-based security tool developed by Thinkst. It lets you plant fake digital breadcrumbs known as canary tokens across your systems. When an attacker touches one of these tokens, you get an instant alert with details like the IP address, user agent, and timestamp. The tool covers common attack surfaces like web links, DNS queries, and cloned documents.

You can generate tokens for AWS keys, Microsoft Word documents, PDFs, Slack API tokens, and MySQL credentials. Each token sends alerts via email, webhook, or Syslog. The project also includes OpenCanary, a full honeypot daemon that runs on Linux and emulates services like SSH, HTTP, and SMB. Thinkst maintains both the hosted service at canarytokens.org and the open-source code on GitHub.

Security teams and penetration testers use Canary Tokens to catch lateral movement early without deploying complex infrastructure. The hosted version is free with no account required. OpenCanary is MIT licensed and runs on any Linux system. Thinkst also offers a commercial enterprise version with advanced features for larger deployments.
Security

Quick Facts

Pricing
Free
License
Open Source
Platform
Linux
Developer
Thinkst