CanarytokensCanarytokens
Home
Guide
Create
GitHub
Home
Guide
Create
GitHub
  • Create
  • Guide

    • Introduction
    • Getting Started
  • Examples

    • How to use the examples
    • Adobe PDF Canarytoken
    • AWS API Keys Canarytoken
    • AWS Infrastructure Canarytoken
    • Azure Entra ID login token
    • Azure Login Certificate Canarytoken
    • Cloned Website Canarytoken
    • Credit Card Canarytoken
    • CrowdStrike Client Credential Canarytoken
    • CSS Cloned Website Canarytoken
    • Custom EXE Canarytoken
    • DNS Canarytoken
    • Fake App Canarytoken
    • HTTP Canarytoken
    • Fake IdP SAML App Canarytoken
    • Kubeconfig Token
    • Log4shell Canarytoken
    • MS Excel Canarytoken
    • MS Word Canarytoken
    • MySQL Dump Canarytoken
    • Network Folder Canarytoken
    • QR Code Canarytoken
    • Fast Redirect Canarytoken
    • Slow Redirect Canarytoken
    • Sensitive Command Canarytoken
    • SQL Server Canarytoken
    • SVG Canarytoken
    • SVN Canarytoken
    • Unique email address Canarytoken
    • Web Image Canarytoken
    • Windows Directory Canarytoken
    • WireGuard Canarytoken

Custom EXE Canarytoken

What is a Custom EXE Canarytoken

This Canarytoken works by signing an EXE or a DLL with a certificate containing a Canarytoken. When the EXE is run, or the DLL is loaded, an alert is fired.

Creating the Canarytoken

Create a Canarytoken by choosing "Custom exe / binary" from the Canarytokens list.

Leave a reasonable comment to remind yourself where you will deploy the Canarytoken. Then, select the EXE or the DLL to be signed.

The file can now be downloaded. Remember, this Canarytoken is triggered whenever the binary file is executed. For EXEs, this means direct execution and for DLLs, it means they were loaded.

What to tokenize

When choosing which files to Canarytoken, decide on a few binaries commonly used by attackers, and Canarytoken these.

Help us improve this page!
Last Updated: 7/23/24, 2:58 PM
Prev
CSS Cloned Website Canarytoken
Next
DNS Canarytoken