Canary Tokens
A free, open-source honeypot tool that deploys fake credentials, URLs, and files to detect intruders in your network.
About Canary Tokens
You can generate tokens for AWS keys, Microsoft Word documents, PDFs, Slack API tokens, and MySQL credentials. Each token sends alerts via email, webhook, or Syslog. The project also includes OpenCanary, a full honeypot daemon that runs on Linux and emulates services like SSH, HTTP, and SMB. Thinkst maintains both the hosted service at canarytokens.org and the open-source code on GitHub.
Security teams and penetration testers use Canary Tokens to catch lateral movement early without deploying complex infrastructure. The hosted version is free with no account required. OpenCanary is MIT licensed and runs on any Linux system. Thinkst also offers a commercial enterprise version with advanced features for larger deployments.
Quick Facts
- Pricing
- Free
- License
- Open Source
- Platform
- Linux
- Developer
- Thinkst