home

drop file access logs or security evtx csv · flag access to honeypot and canary patterns · insider trip wires · runs locally

drop security evtx csv
or click

expects ObjectName + SubjectUserName · event 4663/4656 · optional AccessMask, ProcessName, TimeCreated

add your decoy filenames · regex example: /confidential.*\.xlsx/i

drop 4663/4656 security csv · 230 built-in canary patterns
ready