OSINT Radar

Canarytokens

canarytokens.org

Canarytokens creates tracking traps that alert investigators when accessed, revealing attacker IP, time, and origin when planted.

Free Open Source #Canarytokens #deception token #tripwire alerting #breach detection #compromise detection #honeytoken #incident response #Privacy & Security OSINT
Open tool

Pivot map

You have domain email ip
You get exposure advisories breaches credentials

Use this map to decide whether Canarytokens accepts the lead you are holding, and what kind of lead it may return for the next step.

Pivot from here

Outputs from Canarytokens can become inputs for the next tool. These are the most relevant follow-on pivots in the library.

Investigator Use

Canarytokens is a free honeypot-as-a-service tool that generates unique, trackable URLs, documents, images, and other file types that silently notify the creator when they are opened or accessed. When a Canarytoken is triggered, the creator receives an alert including the accessing IP address, browser information, and timestamp.


For OSINT investigators and security researchers, Canarytokens provide active intelligence gathering capability — rather than passively discovering what a threat actor is doing, investigators can deploy tokens that generate alerts when the threat actor interacts with them.


Document tracking is a primary investigative application. When a Canarytoken-embedded Word document or PDF is sent to a suspect or delivered via a scenario that would cause them to open it, the token fires when the document is opened, revealing the subject's IP address, location, and approximate ISP. This is particularly useful in authorized sting operations or when trying to locate a subject who is otherwise hiding.


Email-based tokens alert when an email with the embedded token is opened — providing evidence that a specific email was received and read, along with the IP from which it was accessed.


Infrastructure monitoring: Canarytokens can be placed in sensitive locations (network shares, web directories, application source code) to alert when those locations are accessed — immediately detecting unauthorized access to protected resources.


DNS-based tokens generate alerts when a specific hostname is queried — useful for embedding in documents or configurations where the hostname would only be queried if someone was examining the content.


Canarytokens are deployed legitimately in security monitoring and authorized investigations. Their use in unauthorized entrapment or deceptive scenarios outside authorized investigative contexts raises legal and ethical concerns that investigators must carefully navigate.


Document any Canarytokens created for investigations with the token type, deployment context, intended subject, and all alerts received including IPs and timestamps.

Before You Pivot

Record Context

Capture the target, search terms, and why this source is relevant before you leave the page.

Preserve Evidence

Archive volatile pages, save screenshots, and keep timestamps for anything that may change.

Corroborate

Treat one tool as a lead source. Confirm important findings with independent sources.

Related tools