Free Honey Tokens for Breach Detection - No Signup
前红队成员开发的欺骗平台提供免费安全令牌服务,包括AWS密钥、S3令牌和SSH私钥等,用于检测内部泄露。用户注册后可获取令牌并放置在敏感位置,一旦被使用将触发警报并提供详细信息如IP地址和时间戳。该服务旨在帮助发现潜在安全漏洞。 2025-12-10 07:39:28 Author: www.reddit.com(查看原文) 阅读量:8 收藏

Howdy folks - former red teamer (a lot of my work is available under the rad9800 alias, if you're interested in malware - check it out!) now building the product to catch me/and in turn the many other adversaries running the same playbooks.   We offer a paid deception platform, but I wanted to make a free tier actually useful.

What's free:

  • AWS Access Keys (10)

  • AWS Bedrock Keys (2)

  • S3 Bucket tokens (2)

  • SSH Private Keys (20)

No credit card, no trial expiry. Just drop your email, get credentials, plant them where they shouldn't be touched. We have 12 other token types in the paid version, and will slowly expand these out in this edition depending on feedback/and increasing limits based on what's being used/what folk want.

Additionally - something unique about our AWS Access Keys in particular you can specify the username and they're allocated from a pool of 1000s of accounts so they're hard/impossible to fingerprint (prove me wrong, I'll be curious).   When someone uses them, you get an alert (via email, which is why we need your email - else we wouldn't!) with:

  • Source IP + geolocation

  • ASN/org lookup

  • VPN/Tor/proxy detection

  • User agent

  • Timestamp

  • Any additional unstructured event metadata

Why these token types?

They're the ones I'd actually look for on an engagement. Hardcoded AWS creds in repos, SSH keys in backup folders, that .env file someone forgot to gitignore. If an attacker finds them, you want to reveal these internal breaches. I've written one or two blogs about "Read Teaming" and the trend (and more than happy to chat about it)

  No catch?  

The catch is I'm hoping some of you upgrade when you need more coverage/scale and/or feedback on this! But the free tier isn't crippled - it is very much the same detection pipeline we use for paying customers!

Link: https://starter.deceptiq.com  

More than happy/excited to answer questions about the detection methodology or token placement strategies.


文章来源: https://www.reddit.com/r/netsec/comments/1piwp1l/free_honey_tokens_for_breach_detection_no_signup/
如有侵权请联系:admin#unsafe.sh