Canarytokens: Token Anything, Anywhere
InfoSec superstar (and long-time Canary fan ) theGrugq recently mused on twitter about generating alerts when certain binaries are run on your hosts. We definitely think it has its uses, and we figured it would be worth discussing a quick way to make this happen (using the existing http://canarytokens.org ) TL;DR : You can pass arbitrary data to a web-token allowing you to use it as a reliable, generic alerter of sorts. We often refer to our Web and DNS Canarytokens as our token ‘primitives’. With these two tokens, you can create traps for attackers nearly anywhere, on any system for any kind of scenario. In fact, nearly all of our other token types are built on top of the Web and DNS tokens. A brief overview of how they work: Web token Visit http://canarytokens.org and create a web token with the label “Fake email in the finance folder of Adrian’s inbox”. The server gives me a unique Canarytoken/link. I place it in the finance folder of Adrian’s inbox. If an attacker clicks/follows ...