Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time. Uses strategically placed decoy documents monitored via file integrity monitoring or OS-level watchdogs to trigger alerts when ransomware modifies or encrypts them. Activates for requests involving ransomware canary deployment, honeyfile setup, deception-based ransomware detection, or file integrity monitoring for encryption.
.claude/skills/deploying-decoy-files-for-ransomware-detection/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-09 | ✗→✓ | ▲ Improved | — | — |
| case-10 | ✗→✓ | ▲ Improved | — | — |
| case-14 | ✗→✓ | ▲ Improved | — | — |
| case-13 | ✗→✓ | ▲ Improved | — | — |
| case-12 | ✗→✓ | ▲ Improved | — | — |
Do not use decoy files as the sole ransomware defense. They are a detection mechanism, not a prevention mechanism, and should complement backups, EDR, and access controls.
watchdog library for cross-platform file system monitoringPlan file placement for maximum detection coverage:
Canary File Placement Strategy:
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Naming Convention:
- Use names that sort FIRST and LAST alphabetically in each directory
- Ransomware typically enumerates directories A-Z or Z-A
- Examples: _AAAA_budget_2024.docx, ~zzzz_report_final.xlsx
Placement Locations:
- Root of every file share (\\server\share\_AAAA_canary.docx)
- Desktop, Documents, Downloads on each endpoint
- Department-specific shares (Finance, HR, Legal)
- Backup staging directories
- Home directories of high-privilege accounts
File Types:
- .docx, .xlsx, .pdf (most targeted by ransomware)
- .sql, .bak (database files, high value)
- Mix of file types to detect ransomware that targets specific extensionsCreate decoy files with realistic content and metadata:
pythonimport os import time def create_canary_docx(filepath, content="Q4 Financial Summary - Confidential"): """Create a realistic .docx canary file using python-docx.""" from docx import Document doc = Document() doc.add_heading("Financial Report - CONFIDENTIAL", level=1) doc.add_paragraph(content) doc.add_paragraph(f"Generated: {time.strftime('%Y-%m-%d')}") doc.save(filepath) def create_canary_txt(filepath): """Create a simple text canary with known content for hash verification.""" content = "CANARY_TOKEN_DO_NOT_MODIFY\n" content += f"Created: {time.strftime('%Y-%m-%dT%H:%M:%S')}\n" content += "This file is monitored for unauthorized changes.\n" with open(filepath, "w") as f: f.write(content)
Monitor canary files for any modification, rename, or deletion:
pythonfrom watchdog.observers import Observer from watchdog.events import FileSystemEventHandler class CanaryHandler(FileSystemEventHandler): def __init__(self, canary_paths, alert_callback): self.canary_paths = set(canary_paths) self.alert_callback = alert_callback def on_modified(self, event): if event.src_path in self.canary_paths: self.alert_callback("MODIFIED", event.src_path) def on_deleted(self, event): if event.src_path in self.canary_paths: self.alert_callback("DELETED", event.src_path) def on_moved(self, event): if event.src_path in self.canary_paths: self.alert_callback("RENAMED", event.src_path)
Define automated responses when canary files are triggered:
Alert Response Matrix:
━━━━━━━━━━━━━━━━━━━━━
Event: Canary MODIFIED
→ Severity: CRITICAL
→ Action: Alert SOC, identify modifying process (PID), isolate endpoint
Event: Canary DELETED
→ Severity: HIGH
→ Action: Alert SOC, check for ransomware note in same directory
Event: Canary RENAMED (new extension added)
→ Severity: CRITICAL
→ Action: Alert SOC, check extension against known ransomware extensions
→ Automated: Kill modifying process, disable network interface
Event: Multiple canaries triggered within 60 seconds
→ Severity: EMERGENCY
→ Action: Network-wide isolation, activate incident response planTest that canary files detect actual ransomware behavior:
bash# Simulate ransomware encryption (safe test - modifies canary content) echo "ENCRYPTED_BY_TEST" > /path/to/canary/_AAAA_budget.docx # Simulate ransomware rename (adds extension) mv /path/to/canary/report.xlsx /path/to/canary/report.xlsx.locked # Verify alerts were generated in SIEM/alerting system
| Term | Definition | |------|------------| | Canary File | A decoy file placed in a directory that is monitored for any access or modification, serving as a tripwire for unauthorized activity | | Honeytoken | A broader category of deception artifacts (files, credentials, database records) designed to alert when accessed | | File Integrity Monitoring | Continuous monitoring of file attributes (hash, size, permissions, timestamps) to detect unauthorized changes | | ReadDirectoryChangesW | Windows API for monitoring file system changes in a directory; used by the watchdog library on Windows | | inotify | Linux kernel subsystem for monitoring file system events; provides near-instant notification of file changes |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-03 | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-09 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-10 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-14 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-13 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-18 | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-15 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-19 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-12 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-20 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-06 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-01 | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-04 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-08 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-07 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-11 | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-17 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-05 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-02 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-16 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-21 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-22 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +32 percentage points is the difference between those two pass rates over the 22 comparable cases.
The per-case answers from this run were removed by the retention sweep, so the case table below shows the verdicts without the text either arm produced. The counts above were recorded at the time and are unaffected. Answers are now kept for 180 days.
Other measured skills in the registry, with their headline benchmark lift.