5. What’s a Canary
For-Pay ones are super feature rich
● Multiple services, multiple HTTP skins
● Magically reports back to thinkst for you (over DNS I believe)
● Configure with their GUI and magically upload to the device
● Slack webhook
● Basic API to retrieve alerts
○ Ended up writing some python to pull these alerts and post into our SIEM because there was
no splunk integration