# cowrie/cowrie

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

Repository: https://github.com/cowrie/cowrie
Canonical: https://ross.abutalabs.com/products/cowrie
Homepage: https://www.cowrie.org/
Language: Python
License: NOASSERTION
License Family: other
Topics: cowrie, honeypot, ssh, telnet, security, kippo, cowrie-ssh, telnet-honeypot, sftp, scp, attacker, threat-analysis, threat-sharing, threatintel, decoy, deception
Last push: 2026-08-24T06:05:46+00:00

## Health v2 (maintenance only)
Score: 99/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 99, longevity 100
- inputs: {"age_days": 4131, "days_push": 9, "days_rel": 10, "gap_med": 6.0, "n_releases_24m": 39}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 6504, forks 1058 (observed 2026-08-28T04:09:43.910471+00:00)

## What it is
Cowrie is a medium-to-high interaction SSH and Telnet honeypot that logs brute-force attacks and full attacker shell sessions, capturing uploaded malware. It can emulate a UNIX filesystem in Python, proxy connections to real backend systems, or use LLMs to generate dynamic shell responses, with output plugins for SIEM platforms.

## Use cases
- detect ssh brute force attacks on my server
- capture malware samples uploaded by attackers
- record attacker shell sessions for threat analysis
- set up an ssh honeypot for threat intelligence
- feed honeypot events into splunk or elasticsearch
- study attacker behavior on telnet
- deceive and monitor attackers with a fake unix shell

## When to choose
- you want to observe and log SSH/Telnet attack activity and collect malware samples
- you need threat intelligence feeds integrated with SIEM tools like Splunk, Sentinel, or Elasticsearch
- you are a security researcher or CERT deploying a widely adopted, actively maintained honeypot

## When to avoid
- you need to protect a production SSH service rather than study attackers
- you require a low-resource, low-interaction sensor only
- you need a honeypot for protocols other than SSH/Telnet

## Facets
- artifact type: application
- maturity: active
- function: security, logging, monitoring, http-server, middleware
- domain: security, self-hosted, developer-tools
- platform: python, self-hosted
- tags: honeypot, ssh, telnet, threat-intelligence, deception, malware-collection, siem-integration, sftp, llm, linux, docker

## Member repositories
- cowrie/cowrie (main) score 99

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:43.910471+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:44:28.832926+00:00, confidence not recorded.
  - readme: https://github.com/cowrie/cowrie (fetched 2026-08-28T04:09:43.910471+00:00, sha 2e6b69bbcfd7)
  - homepage: https://www.cowrie.org/ (fetched 2026-08-29T08:41:55.816043+00:00, sha 2b980bad36ff)
  - site_page: https://www.cowrie.org/features (fetched 2026-08-29T08:41:55.818445+00:00, sha f69061409b7b)
  - site_page: https://www.cowrie.org/about (fetched 2026-08-29T08:41:55.822153+00:00, sha 8e01601ce1e2)
  - registry_pypi: https://pypi.org/pypi/cowrie/json (fetched 2026-08-29T08:41:55.827347+00:00, sha d1a49cb696a2)
  - site_page: https://www.cowrie.org/integrations (fetched 2026-08-29T08:41:55.820311+00:00, sha 08a2b1db3766)
- Data as of 2026-08-30T08:39:29.467469+00:00.
