Skip to content
OpenCatalogcurated by FLOSSK
Security & Privacy

Cowrie

Medium-interaction SSH and Telnet honeypot logging brute-force, shell commands, and file drops with JSON/SFTP export options.

Why it is included

De facto open honeypot for credential-spray telemetry and malware URL collection from botnets.

Best for

Researchers and SOCs capturing attacker TTPs on fake shells without full VM sandboxes.

Strengths

  • Rich session logs
  • File capture
  • Large user base

Limitations

  • Expose only isolated networks; legal notice and monitoring policy required

Good alternatives

OpenCanary · Kippo forks · commercial honeypots

Related tools