Thinkst Canary
You can integrate Thinkst Canary with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Thinkst Canary product overview
Thinkst Canary offers honeypots and tokens designed to detect intruders in your environment. By mimicking genuine assets, Canaries attract attackers and trigger alerts when they're interacted with. These high-fidelity alerts give security teams early warning of potential breaches with minimal false positives.
What we ingest
Sophos XDR collects Thinkst Canary data over HTTPS by polling the Thinkst Canary Console API for incidents, authenticating with a Canary Console API token. The following data is collected:
- Canary incidents: Alerts raised when a Canary device or a Canarytoken is triggered, including the incident type and description, the source and destination host and port, the Canary node, and the underlying triggering event details.
Event and data types
All Thinkst Canary incidents are normalized uniformly to third-party security alert telemetry. They include:
- Canary alerts: Interactions with deployed Canary honeypots, including host and network port scans; SSH, FTP, MSSQL, and SMB login attempts; shared file access; and changes in Canary device connectivity.
- Canarytoken triggers: Activations of deployed Canarytokens, such as cloned-website and credential (for example, AWS API key) token triggers.
Data provided by this integration
Data provided by Thinkst Canary gets normalized to the following schemas:
thirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.