π₯ Someone opened your file. You know their IP address, location, browser and exact timestamp - and they have no idea you know. Here's the free tool that makes it possible. π
It's called Canarytokens, the most powerful free digital tripwire tool on the internet. Used by security researchers, journalists, investigators and intelligence analysts worldwide.
Go to
canarytokens.org/nest
Here's how it works:
You create a trap. You plant it somewhere. The moment anyone touches it β you get an instant alert with their IP address, location, device and exact time.
They announce themselves without knowing it.
20 trap types to choose from:
π Word document - someone opens the file, you get their IP instantly. Plant it in a folder labelled "Passwords" or "Confidential" and wait.
π Tracking URL - send a link. The moment they click it, IP address, browser, operating system, city, country. All logged silently.
π§ Email token - embed in any email. Fires the moment they open it. Know exactly when and where your email was read.
π³ Fake credit card - generate realistic card details. The moment an attacker tries to use them, instant alert. Used by Grafana Labs to detect a breach within minutes in 2025.
π Fake AWS API key - plant it in a file. Any attacker who finds it and tries to use it triggers the alarm immediately.
πΌοΈ QR code - print it and place it anywhere physical. Someone scans it, you get their phone model, location and timestamp.
Real OSINT use cases:
π Send a document to a suspect source, find out if they forwarded it and to whom
π Plant a fake credentials file in a shared drive, know immediately if someone unauthorised accessed it
π Embed a token in a PDF sent to a leak suspect, the moment they open it, you have their IP
π Track whether a sensitive email was forwarded beyond the intended recipient
How to set one up in 60 seconds:
1. Go to
canarytokens.org/nest
2. Select your token type from the dropdown
3. Enter your email address for alerts
4. Add a reminder note - "sent to [name] on [date]"
5. Generate the token
6. Plant it and wait
Zero false positives. Nobody touches a fake AWS key by accident. Nobody opens a file labelled "Confidential Salary Data" unless they're looking for exactly that.
The attacker thinks they found something valuable. They found your trap.
π¬ Have you ever used a digital tripwire to catch someone accessing something they shouldn't? What happened?
π Bookmark this - Canarytokens is the most underused free security tool available to anyone right now.
#OSINT #Canarytokens #BeginnerOSINT #ThreatDetection