Cowrie

Cowrie SSH/Telnet Honeypot

Cowrie (SSH/Telnet-Honeypot)

Cowrie is an open-source medium-interaction honeypot that emulates SSH and Telnet services and records attackers' activities in detail. It feigns a real shell and logs every command entered. It is one of the most widely used honeypots of all.

History & facts. Cowrie emerged from the older honeypot Kippo and significantly extended it (including SFTP support, execution logging, JSON logging). As a medium-interaction honeypot it offers attackers a believable but isolated environment: they can „log in“, issue commands and upload files while everything is meticulously logged — valuable insights into tools, tactics and automated attacks. Cowrie is an integral part of collection platforms such as T-Pot — The All-In-One Multi Honeypot Platform (T-Pot).

Outlook & recommendation. Cowrie delivers excellent data on brute-force attacks, deployed malware and attacker behaviour at exposed SSH services. As with every honeypot: isolate strictly, never store real access or data and control outgoing connections so that the bait is not misused. In the NEOSEC stack, Cowrie is used together with OpenCanary to make attacks visible early and without risk to the productive environment.

Cowrie — Cowrie SSH/Telnet Honeypot