Canary & OpenCanary
What’s a Canary
https://canary.tools
● “Any Interaction” Honeypot
● Mimic “interesting” OS and services
● Any interaction results in an alert
What’s a Canary
https://canary.tools/#how-it-works
What’s a Canary
What’s a Canary
For-Pay ones are super feature rich
● Multiple services, multiple HTTP skins
● Magically reports back to thinkst for you (over DNS I believe)
● Configure with their GUI and magically upload to the device
● Slack webhook
● Basic API to retrieve alerts
○ Ended up writing some python to pull these alerts and post into our SIEM because there was
no splunk integration
What’s a Canary
GUI Set-up
What’s a Canary
Pricing
https://canary.tools/#pricing
Canary pricing allows you to start immediately, with tiny upfront costs. For under
$10k, you get 5 Canaries, a dedicated console, and 5 licences for alerts, support
and maintenance.
OpenCanary
https://github.com/thinkst/opencanary
Thinkst doesn’t currently have VM/OVA but I was told it was in the works
OpenCanary in the meantime
● Not nearly as feature rich
● No slick gui to config (have to use a conf file)
● No recent updates by Thinkst
● But works ok…
● And it’s free
OpenCanary
Decided to use vagrant to spin these things up
OpenCanary
Decided to use vagrant to spin these things up
OpenCanary
OpenCanary
OpenCanary
OpenCanary
Logging
OpenCanary
Logging
OpenCanary
Not Vaporware!
https://github.com/carnal0wnage/vagrant_opencanary

Open Canary - novahackers