deploying-decoy-files-for-ransomware-detection skill (Anthropic-Cybersecurity-Skills)
- Install
- SKILL.md (verbatim)
- When to Use
- Prerequisites
- Workflow
- Step 1: Design Canary File Strategy
- Step 2: Generate Realistic Canary Files
- Step 3: Deploy File System Watcher
- Step 4: Configure Alerting and Response
- Step 5: Validate Detection Coverage
- Verification
- Key Concepts
- Tools & Systems
- Other files in this skill
- references/api-reference.md (verbatim)
- watchdog Library (Python)
- Installation
- Observer Setup
- Event Types
- Handler Methods
- Windows ReadDirectoryChangesW API
- Monitored Changes
- Linux inotify Events
- Event Masks
- Canarytokens (Thinkst)
- Generate Token
- Alert Webhook
- OSSEC/Wazuh File Integrity Monitoring
- Configuration (ossec.conf)
- Alert Rule IDs
- Sysmon File Monitoring
- Event ID 11 - FileCreate
- Event ID 23 - FileDelete
- Common Ransomware File Extensions
What it does. 'Deploys canary files (honeytokens) across file systems to detect ransomware Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
| Upstream | mukul975/Anthropic-Cybersecurity-Skills |
| Skill file | skills/deploying-decoy-files-for-ransomware-detection/SKILL.md |
| License | Apache-2.0 (skill folder LICENSE) |
| Author | mukul975 |
| Fetched | 2026-09-10 |
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-decoy-files-for-ransomware-detection, or copy the skill folder into~/.claude/skills/deploying-decoy-files-for-ransomware-detection/.- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/deploying-decoy-files-for-ransomware-detection/SKILL.md
SKILL.md (verbatim)
name: deploying-decoy-files-for-ransomware-detection
description: 'Deploys canary files (honeytokens) across file systems to detect ransomware
encryption activity in real time. Uses strategically placed decoy documents monitored
via file integrity monitoring or OS-level watchdogs to trigger alerts when ransomware
modifies or encrypts them. Activates for requests involving ransomware canary deployment,
honeyfile setup, deception-based ransomware detection, or file integrity monitoring
for encryption.
'
domain: cybersecurity
subdomain: ransomware-defense
tags:
- ransomware
- detection
- canary-files
- honeytokens
- deception
- file-integrity
version: 1.0.0
author: mahipal
license: Apache-2.0
nist_csf:
- PR.DS-11
- RS.MA-01
- RC.RP-01
- PR.IR-01
mitre_attack:
- T1486
- T1083
- T1490
- T1485
mitre_f3:
version: '1.1'
tactics:
- monetization
- positioning
- stealth
techniques:
- id: F1018
name: Convert to Cryptocurrency
tactic: monetization
source: f3
- id: F1017.001
name: 'Conversion to Physical Monetary Instruments: Cash'
tactic: monetization
source: f3
- id: T1219
name: Remote Access Tools
tactic: positioning
source: attack
- id: T1070
name: Indicator Removal
tactic: stealth
source: attack
Deploying Decoy Files for Ransomware Detection
When to Use
- Setting up early-warning detection for ransomware on file servers or endpoints
- Supplementing EDR/AV with a deception-based detection layer that catches unknown ransomware variants
- Creating high-fidelity ransomware alerts that have very low false-positive rates (legitimate users have no reason to touch decoy files)
- Testing ransomware response procedures by validating that canary file modifications trigger the expected alerting pipeline
- Protecting high-value file shares (finance, HR, legal) with tripwire files that indicate unauthorized encryption activity
Do not use decoy files as the sole ransomware defense. They are a detection mechanism, not a prevention mechanism, and should complement backups, EDR, and access controls.
Prerequisites
- Python 3.8+ with
watchdoglibrary for cross-platform file system monitoring - Administrative access to target file shares or endpoints for canary placement
- File integrity monitoring (FIM) tool or SIEM integration for alert routing
- Understanding of target directory structure to place canaries in high-value locations
- Windows: NTFS change journal or ReadDirectoryChangesW API access
- Linux: inotify support in kernel (standard in modern kernels)
Workflow
Step 1: Design Canary File Strategy
Plan file placement for maximum detection coverage:
Canary File Placement Strategy:
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Naming Convention:
- Use names that sort FIRST and LAST alphabetically in each directory
- Ransomware typically enumerates directories A-Z or Z-A
- Examples: _AAAA_budget_2024.docx, ~zzzz_report_final.xlsx
Placement Locations:
- Root of every file share (\\server\share\_AAAA_canary.docx)
- Desktop, Documents, Downloads on each endpoint
- Department-specific shares (Finance, HR, Legal)
- Backup staging directories
- Home directories of high-privilege accounts
File Types:
- .docx, .xlsx, .pdf (most targeted by ransomware)
- .sql, .bak (database files, high value)
- Mix of file types to detect ransomware that targets specific extensions
Step 2: Generate Realistic Canary Files
Create decoy files with realistic content and metadata:
import os
import time
def create_canary_docx(filepath, content="Q4 Financial Summary - Confidential"):
"""Create a realistic .docx canary file using python-docx."""
from docx import Document
doc = Document()
doc.add_heading("Financial Report - CONFIDENTIAL", level=1)
doc.add_paragraph(content)
doc.add_paragraph(f"Generated: {time.strftime('%Y-%m-%d')}")
doc.save(filepath)
def create_canary_txt(filepath):
"""Create a simple text canary with known content for hash verification."""
content = "CANARY_TOKEN_DO_NOT_MODIFY\n"
content += f"Created: {time.strftime('%Y-%m-%dT%H:%M:%S')}\n"
content += "This file is monitored for unauthorized changes.\n"
with open(filepath, "w") as f:
f.write(content)
Step 3: Deploy File System Watcher
Monitor canary files for any modification, rename, or deletion:
from watchdog.observers import Observer
from watchdog.events import FileSystemEventHandler
class CanaryHandler(FileSystemEventHandler):
def __init__(self, canary_paths, alert_callback):
self.canary_paths = set(canary_paths)
self.alert_callback = alert_callback
def on_modified(self, event):
if event.src_path in self.canary_paths:
self.alert_callback("MODIFIED", event.src_path)
def on_deleted(self, event):
if event.src_path in self.canary_paths:
self.alert_callback("DELETED", event.src_path)
def on_moved(self, event):
if event.src_path in self.canary_paths:
self.alert_callback("RENAMED", event.src_path)
Step 4: Configure Alerting and Response
Define automated responses when canary files are triggered:
Alert Response Matrix:
━━━━━━━━━━━━━━━━━━━━━
Event: Canary MODIFIED
→ Severity: CRITICAL
→ Action: Alert SOC, identify modifying process (PID), isolate endpoint
Event: Canary DELETED
→ Severity: HIGH
→ Action: Alert SOC, check for ransomware note in same directory
Event: Canary RENAMED (new extension added)
→ Severity: CRITICAL
→ Action: Alert SOC, check extension against known ransomware extensions
→ Automated: Kill modifying process, disable network interface
Event: Multiple canaries triggered within 60 seconds
→ Severity: EMERGENCY
→ Action: Network-wide isolation, activate incident response plan
Step 5: Validate Detection Coverage
Test that canary files detect actual ransomware behavior:
# Simulate ransomware encryption (safe test - modifies canary content)
echo "ENCRYPTED_BY_TEST" > /path/to/canary/_AAAA_budget.docx
# Simulate ransomware rename (adds extension)
mv /path/to/canary/report.xlsx /path/to/canary/report.xlsx.locked
# Verify alerts were generated in SIEM/alerting system
Verification
- Confirm all canary files are present and unmodified using stored hash baselines
- Verify that modifying any canary file generates an alert within the expected timeframe (under 30 seconds)
- Test that alert routing to SOC/SIEM is functional with a controlled modification
- Validate that automated response actions (process kill, network isolation) execute correctly
- Check that canary files survive normal backup and restore operations
- Ensure legitimate users and processes are excluded from false-positive alerts (backup agents, AV scans)
Key Concepts
| Term | Definition |
|---|---|
| Canary File | A decoy file placed in a directory that is monitored for any access or modification, serving as a tripwire for unauthorized activity |
| Honeytoken | A broader category of deception artifacts (files, credentials, database records) designed to alert when accessed |
| File Integrity Monitoring | Continuous monitoring of file attributes (hash, size, permissions, timestamps) to detect unauthorized changes |
| ReadDirectoryChangesW | Windows API for monitoring file system changes in a directory; used by the watchdog library on Windows |
| inotify | Linux kernel subsystem for monitoring file system events; provides near-instant notification of file changes |
Tools & Systems
- watchdog (Python): Cross-platform file system event monitoring library supporting Windows, Linux, and macOS
- Canarytokens (Thinkst): Free hosted service for generating various types of canary tokens including files, URLs, and DNS tokens
- OSSEC/Wazuh: Open-source HIDS with built-in file integrity monitoring and alerting capabilities
- Elastic Endpoint: Uses canary files internally for ransomware protection and key capture
- Sysmon: Windows system monitor that logs file creation events (Event ID 11) for canary file monitoring
Other files in this skill
references/api-reference.md (verbatim)
API Reference: Decoy Files for Ransomware Detection
watchdog Library (Python)
Installation
pip install watchdog
Observer Setup
from watchdog.observers import Observer
from watchdog.events import FileSystemEventHandler
observer = Observer()
observer.schedule(handler, path, recursive=True)
observer.start()
observer.join()
Event Types
| Event Class | Trigger |
|---|---|
FileCreatedEvent |
New file created in watched directory |
FileModifiedEvent |
Existing file content or metadata changed |
FileDeletedEvent |
File removed from watched directory |
FileMovedEvent |
File renamed or moved (src_path, dest_path) |
DirCreatedEvent |
New directory created |
DirDeletedEvent |
Directory removed |
Handler Methods
| Method | Called When |
|---|---|
on_created(event) |
File/directory created |
on_modified(event) |
File/directory modified |
on_deleted(event) |
File/directory deleted |
on_moved(event) |
File/directory renamed/moved |
on_any_event(event) |
Any file system event |
Windows ReadDirectoryChangesW API
Monitored Changes
| Flag | Description |
|---|---|
FILE_NOTIFY_CHANGE_FILE_NAME |
File created, deleted, or renamed |
FILE_NOTIFY_CHANGE_DIR_NAME |
Directory changes |
FILE_NOTIFY_CHANGE_SIZE |
File size changed |
FILE_NOTIFY_CHANGE_LAST_WRITE |
Last write time changed |
FILE_NOTIFY_CHANGE_SECURITY |
Security descriptor changed |
Linux inotify Events
Event Masks
| Mask | Description |
|---|---|
IN_MODIFY |
File was modified |
IN_DELETE |
File was deleted |
IN_MOVED_FROM |
File was renamed (old name) |
IN_MOVED_TO |
File was renamed (new name) |
IN_CREATE |
File was created |
IN_ATTRIB |
Metadata changed |
Canarytokens (Thinkst)
Generate Token
URL: https://canarytokens.org/generate
Types: Word document, PDF, DNS, HTTP, AWS key, SQL, SVN
Alert Webhook
POST https://canarytokens.org/webhook
Payload: { "token": "...", "src_ip": "...", "time": "..." }
OSSEC/Wazuh File Integrity Monitoring
Configuration (ossec.conf)
<syscheck>
<frequency>60</frequency>
<directories check_all="yes" realtime="yes">/path/to/canaries</directories>
<alert_new_files>yes</alert_new_files>
</syscheck>
Alert Rule IDs
| Rule ID | Description |
|---|---|
| 550 | File integrity checksum changed |
| 553 | File deleted |
| 554 | New file added to monitored directory |
Sysmon File Monitoring
Event ID 11 - FileCreate
<FileCreate onmatch="include">
<TargetFilename condition="contains">_AAAA_</TargetFilename>
<TargetFilename condition="contains">~zzzz_</TargetFilename>
</FileCreate>
Event ID 23 - FileDelete
Logs file deletions including archived file content.
Common Ransomware File Extensions
| Extension | Family |
|---|---|
| .locked | LockBit, Generic |
| .encrypted | Generic |
| .wncry | WannaCry |
| .dharma | Dharma/CrySiS |
| .basta | Black Basta |
| .lockbit | LockBit 3.0 |
| .conti | Conti |
| .ryuk | Ryuk |
| .revil | REvil/Sodinokibi |
| .akira | Akira |
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.