CanarytokensCanarytokens
Home
Guide
Create
GitHub
Home
Guide
Create
GitHub
  • Create
  • Guide

    • Introduction
    • Getting Started
  • Examples

    • How to use the examples
    • Adobe PDF Canarytoken
    • AWS API Keys Canarytoken
    • AWS Infrastructure Canarytoken
    • Azure Entra ID login token
    • Azure Login Certificate Canarytoken
    • Cloned Website Canarytoken
    • Credit Card Canarytoken
    • CrowdStrike Client Credential Canarytoken
    • CSS Cloned Website Canarytoken
    • Custom EXE Canarytoken
    • DNS Canarytoken
    • Fake App Canarytoken
    • HTTP Canarytoken
    • Fake IdP SAML App Canarytoken
    • Kubeconfig Token
    • Log4shell Canarytoken
    • MS Excel Canarytoken
    • MS Word Canarytoken
    • MySQL Dump Canarytoken
    • Network Folder Canarytoken
    • QR Code Canarytoken
    • Fast Redirect Canarytoken
    • Slow Redirect Canarytoken
    • Sensitive Command Canarytoken
    • SQL Server Canarytoken
    • SVG Canarytoken
    • SVN Canarytoken
    • Unique email address Canarytoken
    • Web Image Canarytoken
    • Windows Directory Canarytoken
    • WireGuard Canarytoken

AWS API Keys Canarytoken

What is an AWS API Keys Canarytoken

This Canarytoken provides you with a set of AWS API keys. Leave them in private code repositories, leave them on a developers machine. An attacker who stumbles on them will believe they are the keys to your cloud infrastructure. If they are used via the AWS API at any point, you will be alerted.

Creating the Canarytoken

Create a Canarytoken by choosing "AWS Keys" from the Canarytokens list.

Leave a reasonable comment to remind yourself where you will deploy the Canarytoken.

The AWS credentials that are displayed can be copied into a file named credentials or keys (as per AWS custom). The two provided keys must be kept together for an attacker to use the AWS API.

The file downloaded contains the AWS API credentials linked to your Canarytoken. The file is formatted such that it looks like a legitimate AWS credentials file.

Note: These alerts first pass through Amazon's logging infrastructure which may introduce a delay of between 2 and 30 minutes before the alert comes through.

Help us improve this page!
Last Updated: 7/23/24, 2:58 PM
Prev
Adobe PDF Canarytoken
Next
AWS Infrastructure Canarytoken