
AI-Powered Cyber Deception Experiment Using Canary Tokens for Threat Detection
The video demonstrates an experiment in AI-powered cyber deception using canary tokens from Thinkst Canary to detect unauthorized access on a computer system. The host, John Hammond, explores automating the deployment of these tokens—such as fake files, DNS requests, or QR codes—via an AI agent to identify optimal placement across a Windows environment. Technical tools include canarytokens.org for generating tokens, webhook.site for alert ingestion, and mailhooks.dev for email-based triggers, with the AI tasked to inventory the file system and deploy tokens autonomously. The proof of concept successfully creates and tests multiple tokens, including a QR code placed on the desktop that triggers alerts when scanned. The experiment highlights the potential for AI to streamline cyber deception without manual intervention, though it acknowledges security risks of granting AI broad system access. Key takeaways emphasize the feasibility of AI-managed deception as a turnkey solution for threat detection.