deploying-honeytokens-and-canarytokens
mukul975/Anthropic-Cybersecurity-Skills
A comprehensive guide to deploying decoy artifacts, such as fake credentials, URLs, and files, called honeytokens or canarytokens. These tokens have no legitimate operational use; therefore, any interaction with them provides a high-fidelity, low-false-positive signal of an intrusion, data theft, or insider threat. Use this technique to enhance detection in low-telemetry areas like file shares or credential stores.