Infrastructure Engineer @ThinkstCanary. @dd@ioc.exchange on Mastodon

Dev Dua retweeted
Well placed canaries and canarytokens are absolutely one of the best pieces of tech you can use as a defender
We built @ThinkstCanary for this. Some of the best security teams in the world use our Canaries && Canarytokens for this. (You can get pretty far with even just our free tokens at canarytokens.org)
5
3
627
Dev Dua retweeted
AI/Agentic attacks have made headlines recently, but agents are highly "suggestible", allowing us to easily detect (or derail) them. Our new "Agent Provocateur" deploys in minutes & works. Read more here, including how to ask agents for reverse shells blog.thinkst.com/2026/09/get…
46
79
691
3,321,207
Dev Dua retweeted
We never ambulance-chase, but there's a good reason that smart security teams have suggested honeypots and deception to detect agentic attacks. Dead simple && Works!
Last month: 🌍 free canarytokens.org were created in ~75% of the countries around the world; 🤯 a single (@ThinkstCanary) customer deployed >500,000 Canarytokens per hour (embedded in their workflows); 💪 we uncovered at least 1 major breach at an AI cloud infra provider
4
14
56
6,135
Dev Dua retweeted
A writeup of @ThinkstCanary & our other tools 🤯🥲💚 "this is my love letter to a company" "something rare in this industry: it made me feel good about detection again" "gave me back .. signal over noise, and something close to joy in the process." linkedin.com/pulse/little-bi…
1
12
21
5,396
Dev Dua retweeted
Replying to @Lodha
@Lodha the approach road to LB has deteriorated badly and has become safety hazard for residents and visitors. As a premium township, the basic access infrastructure should shud be smooth . Request to take up a case with @pcmcindiagovin immediate intervention.
11
4
8
276
Dev Dua retweeted
The World Cup kicks off this Thursday. Now, you can support your team _while_ detecting badness on your network! 💪💚⚽️
5
6
900
Dev Dua retweeted
After not receiving a raise in the four years I’ve worked at BHIS they’ve now decided to reduce my pay by $40k after coming back from maternity leave and moving my role to solely pentesting. So I am looking for a new position effective immediately if anyone has any leads 😇
168
261
1,850
294,226
Dev Dua retweeted
It only took 14 years… but it’s finally here 😊 Meet NexPhone — a smartphone built to run Android, launch Linux (Debian) on demand, and dual-boot Windows 11. My 14-year founder story: nexphone.com/blog/the-tale-o… If you want to support what we’re building, a repost helps a lot.
443
2,096
10,276
648,012
You can grab the latest copy of our quarterly security research roundup at thinkst.com/ts¹ For this issue, we selected work from over 1,370 talks & 1,200 blog posts. Available as PDF, ePUB (or audio highlights) __ ¹ As always, completely free
7
14
1,817
We've always been all about the love.. From all of us, to all of you 💚💚💚
4
7
1,040
We are currently experiencing alerting failures on our Azure login certificate Canarytoken. This affects both free and paid Consoles. The problem appears to be due to changes on Azure - but we are still investigating. We will update with more information when we have it.
1
1
7
1,026
Today we released our new (free) AWS Infrastructure Canarytoken. It catches attackers in your AWS account by putting tempting assets in their way and alerting you if they get probed. Extending our old work on fake AWS assets, this makes it even easier to deploy juicy S3 buckets, DynamoDB tables, SSM parameters, SecretsManager secrets, and SQS queues, that attackers will want to browse. We help you design and build a Terraform module that’s  unique to your environment, then you deploy when ready. It's live on canarytokens.org. Check out our blog for more, including how to deploy your first AWS infrastructure Canarytoken. __ ¹ blog.thinkst.com/2025/09/int…
2
13
55
3,126
It's our birthday, so we created a tiny skunk(worksy) game for you to play.. Complete all 7 continents, and we will send you a limited-edition, 10-year t-shirt. Have fun!! (but watch out for the Canaries) canary.tools/10-year
6
14
55
8,030
In April this year, @grafana had a security incident due to an insecure GitHub Action. The attackers even tried covering their tracks. How were they discovered? Canarytokens.. Check out their (super transparent) post¹ on how they use our tokens at scale.. __ ¹ link follows
6
44
212
21,852
Dev Dua retweeted
Just published a new blog on hashnode—give it a read! ruhika.hashnode.dev/getting-…
3
4
27
2,082
When we first built @ThinkstCanary we were proud that it took less than 4 minutes to be useful when bought. Now it takes less than two... Catching attackers is the game the whole family can play...
3
16
78
4,689
This Valentines your Canary Console offers you a walk down memory lane, with our homage to flappy-bird.. It's a bit of a distance from what we do.. but.. it's also totally what we do 💪💚
3
8
1,045
1) This would be funny if it wasn’t kinda annoying; 2) This definitely isn’t us, don’t fall for it; 3) Crypto stands for cryptography 💪💚
2
6
693
Dev Dua retweeted
Academic work on honeypots and deception are often kinda disappointing, but this paper by @debi_ashenden and Reeves is worth the skim (especially since it confirms lots of our @ThinkstCanary takes 😉) tl;dr : Canaries work, Use ‘em. — ¹ scholarspace.manoa.hawaii.ed…
3
25
84
10,984