Out walking the dog and had a mild heart attack with this @ThinkstCanary alert popup on my phone.

"ipconfig ran on Glenn's desktop"

Seems M$ uploaded the token and analysed it (I created it about four hours ago).
Makes me think of this slide from one of @haroonmeer 's talks.

Basically, you can detect when folks are RE'ing your stuff by hiding various levels of Tokens. e.g one Token that `strings` would find, a deeper one inside a loop that would need to be unpacked, another xor'd one.
And by 'token' here I guess mostly DNS tokens that call home when resolved - best used with a custom Canary token domain.

…http://23b4222d2613a2765d4d432d2d65e88e.topsecret.glenn.com 

(did you know you can use custom domains? I learned that this week)
You can follow @glennzw.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.