← All talks

Canary Tokens: FREE Security Alerts for Hackers! #shorts

BSides Frankfurt1:06980 viewsPublished 2026-03Watch on YouTube ↗
About this talk
Canary Tokens offer free, simple ways to detect intrusions. Generate web bugs, DNS tokens, QR codes, fake app logs, and more to get alerted when attackers access your data or systems. #CanaryTokens #Cybersecurity #ThreatDetection #InfoSec
Show transcript [en]

If we go to the Canary Tokens website, Canary Tokens is free. I don't know if you remember a security researcher, Subt on Twitter, that was coming up with bypass techniques for edrs a number of years ago. He now works at Thinkas and Harun and the team make this available for free. You can generate these Canary tokens where you can create a web bug, a DNS token, a QR code, which is fun. MySQL dump if somebody dumps your database. AWS key. This one's fun because you can put it on a GitHub repository or someplace inside of your organization and as soon as an attacker tries to access that S3 bucket, you get a notification. Fake app log for shell

redirect sensitive command. This one's actually a registry key. Uh sensitive command that if anybody tries to run a command on a computer system, it automatically generates a highle alert. web image, um, uh, uh, Excel spreadsheet, Word document, tons of