Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
coalmine — Cloud Canary Object Orchestration Management Platform | Kitploit
Tools/GitHubGitHub/johnearle/coalmine
Defensive ToolsCloud SecurityIdentity & Access Management (IAM)Intrusion DetectionIncident Response
GitHubjohnearle/coalmine

coalmine

Cloud Canary Object Orchestration Management Platform

View Repository
82141 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Coalmine — Canary Token Management

Cloud Canary Token Management — Deploy, monitor, and rotate deceptive credentials across AWS and GCP to detect unauthorized access.

License

[!WARNING] Alpha Version — Coalmine is in early development. Basic functionality is the current priority, and the application should not be considered fully security tested for production use.

Status

FunctionalDevelopment (Unstable)To Do
AWS IAM User CanariesGCP Service Account CanariesAzure Support
AWS S3 Bucket CanariesGCP Bucket CanariesSIEM Integration
CloudTrail MonitoringGCP Audit Log Monitoring
PostgreSQL State BackendAutomatic Rotation
REST API (API Key + Session Auth)
WebUI Dashboard
Email & Webhook Alerts
Credential & Account Management
RBAC (Casbin)

Overview

Coalmine automatically deploys and monitors "canary tokens" — decoy credentials and resources that trigger alerts when accessed by attackers.

Supported Providers:

  • AWS: IAM Users, S3 Buckets
  • GCP: Service Accounts, Cloud Storage Buckets

Features

  • Multi-Cloud Support — AWS and GCP from a single interface
  • Credential & Account Model — Manage cloud credentials and accounts through CLI, API, or YAML sync
  • Automatic Rotation — Credentials rotate on configurable intervals
  • Centralized Monitoring — CloudTrail and GCP Audit Log integration
  • Flexible Alerting — Email, Webhook, and Syslog notifications
  • Infrastructure as Code — OpenTofu-managed resources
  • REST API — Programmatic access with API key or session authentication
  • WebUI — Browser-based dashboard at /ui
  • RBAC — Role-based access control via Casbin
  • CLI — Grouped subcommand structure (coalmine <resource> <action>)

Quick Start

Prerequisites

  • Docker & Docker Compose
  • AWS credentials (for AWS canaries)
  • GCP credentials (for GCP canaries)

1. Clone & Configure

git clone https://github.com/yourorg/coalmine.git
cd coalmine
cp .env.example .env
# Edit .env with your database and cloud credentials

2. Start Services

docker compose up -d

This starts the API, Celery worker, Redis, and PostgreSQL. The WebUI is available at http://localhost:8000/ui.

3. Register Credentials & Accounts

# Add an AWS credential
docker compose exec app coalmine credentials add my-aws-cred AWS \
  --secrets '{"access_key_id": "...", "secret_access_key": "...", "region": "us-east-1"}'

# Add an account under that credential
docker compose exec app coalmine accounts add prod-east --credential my-aws-cred \
  --account-id 111111111111

# Or sync credentials and accounts from YAML config
docker compose exec app coalmine credentials sync --dry-run

4. Create a Logging Resource

# Create CloudTrail logging destination
docker compose exec app coalmine logs create my-trail AWS_CLOUDTRAIL \
  --account <ACCOUNT_ID>

# List logging resources
docker compose exec app coalmine logs list

5. Deploy a Canary

# Create an AWS IAM User canary
docker compose exec app coalmine canary create my-canary AWS_IAM_USER \
  --account <ACCOUNT_ID> --logging-id <LOGGING_ID>

# List canaries
docker compose exec app coalmine canary list

6. Verify Detection

# Trigger a test alert
docker compose exec app coalmine canary trigger my-canary

# Wait for monitoring cycle (~1 min) then check alerts
docker compose exec app coalmine alerts list

Architecture

┌─────────────┐   ┌─────────────┐   ┌─────────────┐
│     CLI     │   │  REST API   │   │   WebUI     │
│  (coalmine) │   │  (FastAPI)  │   │  (React)    │
└──────┬──────┘   └──────┬──────┘   └──────┬──────┘
       │                 │                 │
       └────────┬────────┴────────┬────────┘
                │                 │
                │          ┌──────▼──────┐
                │          │Auth / RBAC  │
                │          │  (Casbin)   │
                │          └──────┬──────┘
                │                 │
         ┌──────▼─────────────────▼──────┐
         │         Celery Workers        │
         │  (Canary · Monitoring · Logs) │
         └──────────────┬────────────────┘
                        │
      ┌─────────────────┼─────────────────┐
      │                 │                 │
┌─────▼─────┐   ┌──────▼──────┐   ┌──────▼──────┐
│ OpenTofu  │   │  Monitors   │   │Notifications│
│ Templates │   │(CloudTrail/ │   │(Email/Hook/ │
│           │   │ Audit Logs) │   │   Syslog)   │
└─────┬─────┘   └──────┬──────┘   └─────────────┘
      │                │
┌─────▼─────┐   ┌──────▼──────┐
│ AWS / GCP │   │   Alerts    │
│(Resources)│   │    (DB)     │
└───────────┘   └─────────────┘

          ┌─────────────────┐
          │   PostgreSQL    │
          │   (Inventory)   │
          └────────┬────────┘
                   │
          ┌────────▼────────┐
          │   Celery Beat   │
          │   (Scheduler)   │
          └─────────────────┘

CLI Reference

Commands follow the pattern: coalmine <resource> <action> [options]

Canary Commands

CommandDescription
canary create <name> <type>Create a new canary
canary listList all canaries
canary delete <name_or_id>Delete a canary
canary creds <name>Get canary credentials
canary trigger <name_or_id>Test canary detection

Credential Commands

CommandDescription
credentials listList all credentials
credentials add <name> <provider>Add a credential
credentials update <name_or_id>Update a credential
credentials remove <name_or_id>Remove a credential
credentials validate <name_or_id>Validate credential health
credentials sync [--dry-run]Sync from YAML config

Account Commands

CommandDescription
accounts list [--credential <name>]List all accounts
accounts add <name>Add an account
accounts update <name_or_id>Update an account
accounts enable <name_or_id>Enable an account
accounts disable <name_or_id>Disable an account
accounts remove <name_or_id>Remove an account
accounts validate <name_or_id>Validate account health

Logging Commands

CommandDescription
logs create <name> <type>Create logging resource
logs listList logging resources
logs scan --account <id>Scan existing CloudTrails

Alert Commands

CommandDescription
alerts list [--canary <name>]View security alerts

Auth Commands

CommandDescription
auth key listList API keys
auth key add <name>Add an API key
auth session listList active sessions

User Commands

CommandDescription
user listList all users
user rolesList available roles

Task Commands

CommandDescription
task listView recent async tasks
task status <task_id>Check task result

Help

docker compose exec app coalmine --help
docker compose exec app coalmine canary --help

REST API

The API runs at http://localhost:8000 and requires authentication via API key header or session cookie.

Configuration (config/api_keys.yaml)

api_keys:
  - key: "your-api-key-here"
    name: "admin"
    permissions: ["read", "write"]
    scopes: ["all"]

Example Requests

Download Tool