Building canaries with ELK and ElastAlert2
Andrew Januszak, Keith Erekson
BSides NYC 2024 · Day 1 · Tech - Blue
In "Building Canaries with ELK and ElastAlert2," Andrew Januszak and Keith Erekson from Lehigh University present a practical, cost-effective approach to enhancing organizational security through the strategic deployment of **canaries** and **honey tokens**. As members of a systems engineering team, their focus is on leveraging existing infrastructure to create "low effort, high gain" defensive tools that provide immediate, event-driven alerts when something unexpected or malicious occurs. This talk delves into how their team implemented these proactive measures using the **ELK Stack** (Elasticsearch, Logstash, Kibana) and **ElastAlert2**, specifically targeting gaps left by traditional security controls and vendor tooling.
AI review
Competent, honest practitioners sharing a real deployment with real results — exactly what a BSides slot is for. Nothing here will surprise anyone who's read the Thinkst Canary docs or played with canarytokens.org, but the SSO JavaScript canary catching live phishing campaigns before mass sends is a genuinely useful data point, and the false-positive taxonomy is the kind of operational scar tissue you only get from actually running this stuff.