Canarytokens were highlighted as a practical detection mechanism for both insider-threat investigations and attacker activity, including unauthorized access to sensitive files and post-exploitation behavior. In one case, investigators placed an Excel XLSX canarytoken around a suspected customer mailing list so that opening or parsing the document would trigger an outbound request and reveal access details such as the source IP address. The technique relies on embedding an external resource reference inside the Open XML package, allowing defenders to detect when a decoy or monitored document is touched.
The same reporting showed that canarytokens can also surface adversary tradecraft unexpectedly during intrusion activity. A sensitive-command token fired when a Cobalt Strike Elevate Kit user account control bypass invoked whoami, providing an early signal of hands-on-keyboard attacker behavior. The examples underscore that canarytokens can supplement detection and investigation workflows, but they do not replace core defenses such as EDR, patching, MFA, Active Directory hardening, and least-privilege controls.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
dfir.ch published an article describing the Excel canarytoken and sensitive-command canarytoken case studies, concluding that Canarytokens can provide useful early warning but are not a replacement for EDR and broader security controls.
Oddvar Moe published a blog post describing persistence using GlobalFlags in Image File Execution Options, the technique later cited as the basis for a sensitive-command canarytoken use case.
In a separate incident response case, threat actors executed or attempted the Cobalt Strike command "elevate uac-schtasks." During analysis, a previously installed whoami-sensitive-command canarytoken generated a DNS alert because the underlying technique runs "whoami /groups" to check group membership and integrity level.
The demonstrated XLSX canarytoken file was uploaded to an online Excel parsing platform, and parsing it triggered an alert email indicating that the document had been opened or processed. The article explains this worked because the XLSX contained an external relationship pointing to a canarytokens.com URL.
To determine whether the Excel data was being stolen or improperly accessed, an Excel canarytoken document was generated for controlled placement with suspected insiders or on the web server.
A company found that upcoming customer mailing targets were repeatedly leaking, with competitors contacting the same customers one or two days earlier. The suspected causes were either an insider threat or compromise of the external web server used to process uploaded Excel files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
dfir.ch
Open sourceoddvar.moe
Open sourcecanarytokens.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.