Complete list of enterprise security products I recommend (evergreen edition): 1) @ThinkstCanary 2) @duosec 3) @Yubico
Customer Love
We have a tiny sales-team, but our Canaries have a pretty awesome footprint (hundreds of thousands of tokens have been minted and Canaries are running on all 7 continents). This only happens because of our awesome customers. It’s pretty rare to find a security product that people can tolerate. It’s near impossible to find one that customers love.
Contact us“Thinkst Canary builds the best security product for the dollar period. Their technology has driven a paradigm shift in detection engineering. For a fraction of the cost of other security tools Thinkst has provided more insight around adversarial behavior by producing only high fidelity alerts...”
“Over the years, there were numerous examples of Canary saving us where multi-million dollars solutions did not live up to their names, but one particular is worth mentioning because it gave us visibility into the things that are often overlooked as a risk...”
“Thinkst Canary builds the best security product for the dollar period. Their technology has driven a paradigm shift in detection engineering. For a fraction of the cost of other security tools Thinkst has provided more insight around adversarial behavior by producing only high fidelity alerts...”
I have to give a shout out to @ThinkstCanary for being awesome. They not only have a great product but also great people behind it. 🦅
Out with the old @ThinkstCanary's and in with the new. If you have not deployed these on your network you are missing a great tool.
You may be wondering "does @ThinkstCanary actually work?" Yes. Yes it does. #NoContext
You could buy a threat intel feed, or you could just buy a canary from canary.tools and know when you’be been breached #CTIJam
If you have networks, and you care about protecting them, go give @haroonmeer some coins for a bag of @ThinkstCanary. They’re ace.
So excited to see how this bird works. cc: @ThinkstCanary @haroonmeer
just got a demo of @ThinkstCanary by @haroonmeer... HO-LEEE CRAP!!! what a beautifully designed, powerful product #honeypot #infosec
1) Guy leaves token'd doc on WebServer (not in document root) 2) Token is hit from Russian IP Address Seriously use canarytokens.org
But probably what you actually want is @ThinkstCanary
How many other "security products" are positively evaluated when anyone with a clue looks at them?
We had the smart folks at @NCCGroupInfosec do a security audit on Canary (to add to our customers peace of mind) https://t.co/oKvrWepTMK “Overall, Thinkst have done a good job and shown that they are invested in producing not only a security product but also a secure product”
btw, @ThinkstCanary support is as awesome as their product. unfortunately i had to test it, and have been extremely impressed. and i sure sleep better at night with a bird on the wire.
If you don't have canary seriously check it out canary.tools @ThinkstCanary #infosec #DFIR
As a current customer I highly recommend the @ThinkstCanary. You won’t initially think it’s doing much of anything until it does and uncovers a quagmire of a situation you didn’t know you had (speaking from experience here)
Don’t think, just get them ;). I was a former customer (changed roles). What will you get from them? The best support, easy interface, great price and the most accurate alert in your environment. #canarylove
Glad to see @ThinkstCanary gaining traction. It's a simple but highly effective tool for network defenders.
When you find out from your canaries that the scanning team are testing new scanners before your IPS O_o Thanks @ThinkstCanary
Been chatting to @haroonmeer about @ThinkstCanary. This is super cool, honeypots made ridiculously easy: canary.tools
Just did quick and dirty Canary Token demo for a coworker. @haroonmeer the simplicity, flexibility, and power of this tool is inspiring.
Even if you don’t have budget get over to canarytokens.org and use their amazing free service.
"Our Canaries are made to look valuable, not vulnerable" ... that's what makes @ThinkstCanary very effective! we <3 canary.tools
canary.tools <-- This I like! Low friction honeypot devices.
I had some broken @ThinkstCanary's after a power outage and they RMA'ed new ones from South Africa in under 4 days. Amazing support!
Traps, tarpits, and honey tokens just plain work - now available for free at canarytokens.org
It was great to finally meet @haroonmeer :) Dude, people only say good things about @ThinkstCanary. Congrats!
Setting up #honeypots will never be the same with #Canaries. Check out canary.tools by @haroonmeer. So cool..
Set aside an hour to setup my new @ThinkstCanary ... not sure what I'm going to do with the other 55 minutes.
Yes. In the DC Cisco Tetration would flag unusual traffic, in the wider estate @ThinkstCanary FTW
1. BeyondCorp: Not easy, or for everyone, but I love the idea. 2. Canaries canary.tools
Just realized the magic of canarytokens.org. Splendid work. Thanks for the info mate
The @ThinkstCanary device is a thing of beautiful uncomplicated simplicity. Thoroughly enjoying putting it through its paces
Here's what other smart people say about @ThinkstCanary (140 character testimonials) canary.tools/love
It has to be said that @duosec, @ThinkstCanary and @XipiterSec are all proof that hackers *can* actually build excellent defensive tech.
Get canary.tools, it can’t protect against shitty security products but at least you’ll know they failed
+100 on the fake AWS creds feature from the @ThinkstCanary team. Super useful insight as we showed at ReInvent.
PS this is now yet another reason I 🖤 @ThinkstCanary — their canaries are certified to be mansplaining-free
Upgrading from @ThinkstCanary V1 to V2 is almost the easiest upgrade you will ever have to do.
My most favourite blue team tip from my defending days 1. Use @ThinkstCanary to create an exe, rename it to ntdsutil.exe and put it in the same directory (C:\Windows\system32) 2. Often attackers will use this to backup ntds.dit 3. Wait for the canary to chirp and then 😎
This why I've been following @ThinkstCanary closely for a while and highly recommend them. Amazing product, developed by some of the most seasoned pros in the industry. Oh, they’re pretty cool guys too. ;)
At the end of the day the business only cares about financial losses resulting from a breach. From the incident data I’ve seen, financial impact strongly correlates to detection & response speed. The faster a breach is identified and mitigated the less the financial impact.
I am often encouraged by the work that @haroonmeer and the folks at @ThinkstCanary are doing. Haroon and team have really proven out the fact that simple, elegant security solutions can scale without VC; it's inspiring!
You know who cares about securing their customers? Companies who make their product easy to use, and affordable. This is why @duosec was valued in the Billions. This is why people love @ThinkstCanary.
I agree with this. @ThinkstCanary provide great products as well as great customer service to go along with them. Well done!
I was wondering why my Canarytoken (a file folder) was triggering & discovered the culprit was chrome.exe. Turns out @googlechrome quietly began performing AV scans on Windows devices last fall. Wtf m8? This isn’t a system dir, either, it’s in \Documents\
The two spends I’d do to increase resilience for less than one blinkenlights magic bullet cybersecurity solution? - @duosec 2FA all the things - @ThinkstCanary gain visibility on when you get penetrated Lots more I’d do w/ Canary Tokens, but that’s custom work g@comae.io 😄
less than 1hr into our internal pentest last week and the @ThinkstCanary were shouting at them. Love it.... #justworks @ronnieapteker @haroonmeer
Enterprise security products that are awesome and you should try: 1) @Cloudflare 2) @Dome9 3) @duo_labs 4) @ThinkstCanary 5) @Yubico
Amazing solution and service. Love @ThinkstCanary
very cool @ThinkstCanary . Nothing like that feeling when you see a new text coming in from your token :D
@haroonmeer and all the folks at @ThinkstCanary are magnificent. A great product, enhanced by superior dedication to customer satisfaction!
Top customer service from @haroonmeer and @ThinkstCanary ! Awesome stuff
The folks at @ThinkstCanary do some great work. We've deployed their devices for various clients as it fulfills many needs in a way that is unmatched.
Love @ThinkstCanary tokens! Once again their use was proven!
as a customer (my goodness, almost two years now) of Thinkst, I can't point to a single interaction where folks weren't awesome.
@haroonmeer @ThinkstCanary Sounds so simple! Feel it might be difficult to teach to new employees. Is it something you pay extra attention to when someone joins? Or is it such a core part of the company everyone learns? And even when you try to keep promises it's easy to forget something when you are busy.
I <3 @ThinkstCanary Canary tokens.
@haroonmeer and the folks at @ThinkstCanary never cease to amaze me with their absolute client centricity. It can not be clearer that their priority is making a great product and building a sustainable relationship with their clients. Bravo!
I don't know if I've said this publicly before, but @ThinkstCanary has always been the company that I've drawn the most inspiration from for @GreyNoiseIO WRT client-centricity and pragmatism, and @haroonmeer has always been one of the founders I've aspired to emulate the most.
I took a @ThinkstCanary canary for a test drive. Out of the box and setup in under 10 mins. Totally working and does what it says on the tin. Im officially a fanboi
@UK_Daniel_Card @ThinkstCanary @ThinkstCanary does indeed rock - brilliant tech, brilliant concepts and brilliant people - fantastic customer service yeah so straightforward to connect into monitoring - MS Sentinal logicapp and done in an hour (including thinking about tea making the tea and drinking the tea)
If you have vendors, you have supply chain issues... Last I checked, unless you are REALLY into running Gentoo or making your own hardware (*cough* Google *cough*) - even THEN you're still not "safe" - your BEST bet is using those canaries to hopefully tip you off early enough
@jeremiahg True positive detection is why I like @ThinkstCanary so much. And other related approaches to detecting compromise that utilise attackers taking positive steps to further their access or exploit their access. That’s where I think there is a viable future against attackers
"The first time (if the red team doesn't know) they'll get caught and then what will happen is the next time around, red-team will second guess every little thing they do & it will slow them down" "Put them anywhere. Put them everywhere" @malcomvetter on Canaries/Canarytokens
If you asked me to name three classes of (defensive) security tech that actually, definitely work I would say canaries, 2fa and then pause for a really long time
If you are at #RSAC and pop over to the North Hall, we will be happy to demo Canary, talk tokens or just chat on general hackery. On Tuesday, you can catch @haroonmeer in the South Expo Briefing Center at 17h10, talking about Birds (and why you should probably be using them).
Apropos to my last tweet, there is an alternative to crappy security products:
#VB2019 has released the vid of our closing talk: “The Products we Deserve” https://t.co/MNJrC9my2F It’s light weekend watching & hopefully gets more ppl to see that we can push back against “the way things have been done” That we can build products & companies that suck less.