๐Ÿค Canary tokens & decoys for the security community

Canary tokens & decoys
for the ones doing the hunting.

Plant a tripwire anywhere โ€” a URL, a tracking pixel, a document, a DNS name โ€” and know the moment someone touches it. Built for security researchers, pentesters and red teamers doing OSINT and threat-landscape work.

Canary types

Pick a decoy. Each one logs the IP, user-agent and full request the instant it fires.

Web URL (webhook)

A unique URL that logs every visit. Drop it where only an intruder would look.

Deploy โ†’

Tracking image

An image (1ร—1 pixel up to a full banner/SVG) that fires when loaded.

Deploy โ†’

Redirect URL

Logs the visit, then forwards the browser to a destination you choose.

Deploy โ†’

QR code

A QR that routes through us (MITM) and forwards to your URL, logging the scan.

Deploy โ†’

JS / CSS asset

A script or stylesheet that reports the referring page/domain that loaded it.

Deploy โ†’

Social share link

A shareable link with custom OpenGraph/Twitter meta that logs unfurls & clicks.

Deploy โ†’

Document

Word/PDF documents with an embedded tracker that fires on open.

Deploy โ†’

Email address

A catch-all inbox address; delivery to it triggers the canary.

Deploy โ†’

DNS token

A hostname under our delegated zone; any DNS lookup of it fires the canary.

Deploy โ†’

Windows folder

A folder with a desktop.ini that fires when browsed in Explorer.

Deploy โ†’

Windows shortcut

A .lnk shortcut whose icon fires when the folder is merely viewed.

Deploy โ†’

Fake login portal

A convincing decoy login page; visits (and typed usernames) are logged.

Deploy โ†’

Secrets / config file

A realistic .env / kubeconfig / creds file with an embedded canary endpoint.

Deploy โ†’

Calendar invite

An .ics invite with a tracking image that fires when the invite is opened.

Deploy โ†’

Cloned-site beacon

A JS snippet for your pages that fires when run on a foreign (phishing) origin.

Deploy โ†’

AWS API key

A deny-all AWS IAM key you deploy via our generated template; any use alerts you.

Deploy โ†’

Log4Shell / JNDI

A ${jndi:...} string that fires when a vulnerable Log4j pipeline resolves it.

Deploy โ†’

Loads from anywhere

Pixels, scripts and stylesheets are served with open CORS so your decoys embed on any origin โ€” an email, a foreign site, a stolen repo.

Stay signed in

A trigger can take days. Sessions last a week and remember you, so you're never locked out while you wait for the trap to spring.

Alert your way

Route hits to Discord, Slack, a raw webhook or email. Everything โ€” types, settings, logs โ€” is driven from the database.