The Open-Source SSH and Telnet Honeypot
Cowrie logs brute-force attacks and the shell sessions attackers perform, captures uploaded malware, and feeds it all to your analysis tools. Free and open source, run by security researchers worldwide.

Cowrie logs brute-force attacks and the shell sessions attackers perform, captures uploaded malware, and feeds it all to your analysis tools. Free and open source, run by security researchers worldwide.

From malware collection to real-time threat intelligence, Cowrie gives security teams and researchers the tools to observe attackers on their own terms.
Capture every aspect of attacker behavior with comprehensive session recording. Monitor commands, keystrokes, and malware downloads in real time, and replay entire sessions afterwards.
Integrate directly with your existing security infrastructure including Splunk, Microsoft Sentinel, and Elasticsearch. Get real-time threat intelligence feeds and automated alerting for immediate response.
Cowrie combines proven honeypot technology with modern security operations and threat intelligence capabilities.
Cowrie's sophisticated honeypot technology captures and analyzes SSH and Telnet attacks, providing comprehensive threat intelligence for your security operations.
Cowrie provides real-time session recording and malware collection capabilities that integrate seamlessly with your existing security infrastructure.
Generate actionable threat intelligence from captured attack data to strengthen your overall security posture.
24/7 automated monitoring with instant alerts for suspicious activity and attack patterns.
Direct integration with popular SIEM platforms including Splunk, Elasticsearch, and Microsoft Sentinel.
Cowrie provides comprehensive threat detection and analysis capabilities. From malware collection to real-time session monitoring, it delivers the intelligence you need to understand the attacks against your network.
Advanced emulation of SSH and Telnet services to capture and analyze attacker behavior in real-time.
Automatically downloads and stores malware samples uploaded by attackers for comprehensive threat analysis.
Complete capture of attacker sessions including commands, keystrokes, and interactions for forensic analysis.
Output plugins for security platforms like Splunk, Microsoft Sentinel, and Elasticsearch.
Real-time attack data and behavioral analysis to identify emerging threats and attack patterns.
A fake filesystem resembling a Debian installation lets attackers explore, download files, and upload malware safely.