cowrie/cowrie
Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/ observed · 2026-08-28
Health v2 · maintenance only
99/100
- Activity 99
- Release rhythm 99
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 6.0
- age_days: 4131
- days_rel: 10
- days_push: 9
- n_releases_24m: 39
Adoption not part of the score
6504 stars · 1058 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Cowrie is a medium-to-high interaction SSH and Telnet honeypot that logs brute-force attacks and full attacker shell sessions, capturing uploaded malware. It can emulate a UNIX filesystem in Python, proxy connections to real backend systems, or use LLMs to generate dynamic shell responses, with output plugins for SIEM platforms.
Use cases
- detect ssh brute force attacks on my server
- capture malware samples uploaded by attackers
- record attacker shell sessions for threat analysis
- set up an ssh honeypot for threat intelligence
- feed honeypot events into splunk or elasticsearch
- study attacker behavior on telnet
- deceive and monitor attackers with a fake unix shell
When to choose
- you want to observe and log SSH/Telnet attack activity and collect malware samples
- you need threat intelligence feeds integrated with SIEM tools like Splunk, Sentinel, or Elasticsearch
- you are a security researcher or CERT deploying a widely adopted, actively maintained honeypot
When to avoid
- you need to protect a production SSH service rather than study attackers
- you require a low-resource, low-interaction sensor only
- you need a honeypot for protocols other than SSH/Telnet
Facets
application · maturity active
security logging monitoring http-server middleware security self-hosted developer-tools python self-hosted honeypot ssh telnet threat-intelligence deception malware-collection siem-integration sftp llm linux docker
6 sources
- readme: https://github.com/cowrie/cowrie · fetched 2026-08-28 · 2e6b69bbcfd7
- homepage: https://www.cowrie.org/ · fetched 2026-08-29 · 2b980bad36ff
- site_page: https://www.cowrie.org/features · fetched 2026-08-29 · f69061409b7b
- site_page: https://www.cowrie.org/about · fetched 2026-08-29 · 8e01601ce1e2
- registry_pypi: https://pypi.org/pypi/cowrie/json · fetched 2026-08-29 · d1a49cb696a2
- site_page: https://www.cowrie.org/integrations · fetched 2026-08-29 · 08a2b1db3766
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| cowrie/cowrie | main | 99 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem