Thinkst Canary is a threat detection solution that utilizes deployable honeypots to identify unauthorized network access and malicious lateral movement. The system deploys hardware, virtual, and cloud-based sensors that impersonate standard network assets such as Windows file servers, Linux web servers, and routers. When an intruder interacts with these decoy systems by browsing file shares, attempting logins, or scanning for open services, the device immediately triggers a security alert.
The platform operates without anomaly detection or machine learning, relying instead on high-fidelity interaction markers to eliminate false positives. Devices communicate securely with a hosted management console via outbound DNS queries, simplifying network configuration. The solution also includes Canarytokens, which are deployable digital tripwires such as fake API keys and misleading documents that alert administrators upon unauthorized interaction.