/canarytokendetector

Detect and remove the presence of canary tokens

Primary LanguageShellGNU General Public License v3.0GPL-3.0

Thinkst Canarytokens Detector and Diffuser/Nullifier

A simple script to detect and remove Canary Tokens

image

Installation (tested on MacOS 14)

git clone https://github.com/referefref/canarytokendetector.git
cd canarytokendetector
brew install pdftk-java python3 python3-pip -y
pip3 install pefile
wget https://raw.githubusercontent.com/DidierStevens/DidierStevensSuite/master/disitool.py

Examples

Example running in directory, test-only mode with report output

image

Example running in nullify, verbose, directory mode (vdf)

image

Background and warranty

I wrote this script to augment a chapter on a book I'm writing about deception technologies, specifically around detection mechanisms for tokens. The detections are simple signature based detections which could easily be adjusted or randomised by Thinkst in future. This exists as a PoC, and no warranty of any is provided for the use (or misuse) of this application. Your actions are your own. You execute this at your own risk.