canary-SKILL.md

Deploys DNS, HTTP, and AWS canary tokens with webhook alerts for unauthorized access detection.

Updated Apr 20, 2026
One-click install
npx skills add https://github.com/DCx7C5/ai-marketplace --skill canary-skill-md
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: canary-SKILL.md
Source: https://github.com/DCx7C5/ai-marketplace/tree/main/skills/deception/canary
Command: npx skills add https://github.com/DCx7C5/ai-marketplace --skill canary-skill-md

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires requests, and includes scripts (resource) and references (resource) components.

What problem does it solve?

Canary tokens deploys DNS, HTTP, and AWS API key canary tokens across network infrastructure to detect unauthorized access and lateral movement. Integrates with webhook alerting (Slack, Teams, email, generic HTTP) for real-time intrusion notifications. Provides automated token generation, placement strategies, and monitoring for enterprise network environments.

Core Features & Use Cases

  • Token generation and placement strategies: Deploy DNS, HTTP, and AWS canary tokens across intranet and cloud assets.
  • Real-time alerting and integration: Forward alerts via Slack, Teams, email, or generic webhooks to SOC workflows.
  • Enterprise deployment: Uses Canarytokens.org for token generation and Thinkst Canary API for large-scale management; supports deployment planning by network zone.
  • Deployment planning and SOC readiness: Guides token placement across DMZ, internal, production, and cloud zones to maximize coverage.

Quick Start

Run the agent with full deployment to generate and deploy tokens and produce a deployment report.

Frequently Asked Questions about canary-SKILL.md

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I deploy canary tokens to detect unauthorized network access?

You can deploy DNS, HTTP, and AWS canary tokens across your network infrastructure using Canarytokens.org for token generation and the Thinkst Canary API for large-scale enterprise management and monitoring.

What is the best way to route canary token alerts to my SOC workflow?

Canary token alerts route to SOC workflows via configured webhooks, sending real-time intrusion notifications through Slack, Microsoft Teams, email, or generic HTTP endpoints when tokens are triggered.

Can I use canary tokens for intrusion detection in both cloud and internal network zones?

Canary tokens support intrusion detection across DMZ, internal, production, and cloud zones, providing deployment planning to maximize coverage and detect lateral movement in enterprise network environments.

How does a webhook-based canary token detect lateral movement?

Canary tokens detect lateral movement by placing deceptive DNS, HTTP, and AWS API keys across infrastructure; when an intruder triggers a token, a webhook sends a real-time alert to the monitoring endpoint.

Do I need the Thinkst Canary API to generate deception tokens?

You do not need the Thinkst Canary API for basic generation; Canarytokens.org provides standalone token creation, while the API supports large-scale enterprise deployment and management workflows.