Canary Tokens
Plant a tripwire anywhere — a URL, a pixel, a document, a DNS name — and know the moment somebody touches it.
A canary token is a thing that has no legitimate reason to be used, placed somewhere only an intruder would look. Touch it and it tells on them. The service mints them in a long list of shapes — a logging URL or redirect, a tracking image, a QR code, a script or stylesheet that reports the page that loaded it, a Word or PDF document, an email address, a hostname under our zone, a Windows folder or shortcut that fires on merely being viewed, a decoy login portal, a realistic .env or kubeconfig, a deny-all AWS key, even a JNDI string for a vulnerable Log4j pipeline. Each one logs the IP, user agent and full request the instant it fires, and there is an API so the whole thing can be scripted into an engagement.