Skip to main content

Cowrie

What is Cowrie

Cowrie is a medium to high interaction SSH and Telnet honeypot designed to log brute force attacks and the shell interaction performed by the attacker. In medium interaction mode (shell) it emulates a UNIX system in Python, in high interaction mode (proxy) it functions as an SSH and telnet proxy to observe attacker behavior on another system. In LLM mode, it uses large language models to generate dynamic responses to attacker commands.

Cowrie is maintained by Michel Oosterhof.

Documentation

The Documentation can be found here.

Slack

You can join the Cowrie community at the following Slack workspace.

Features

  • Choose to run as an emulated shell (default):
    • Fake filesystem with the ability to add/remove files. A full fake filesystem resembling a Debian 5.0 installation is included

    • Possibility of adding fake file contents so the attacker can cat files such as /etc/passwd. Only minimal file contents are included

    • Cowrie saves files downloaded with wget/curl or uploaded with SFTP and scp for later inspection

  • Or proxy SSH and telnet to another system
    • Run as a pure telnet and ssh proxy with monitoring

    • Or let Cowrie manage a pool of QEMU emulated servers to provide the systems to login to

  • Or use an LLM backend (experimental):
    • Use large language models (e.g., OpenAI GPT) to dynamically generate realistic shell responses

    • Handles any command without predefined responses

    • Maintains conversation context for consistent sessions

For both settings:

  • Session logs are stored in a User Mode Linux compatible format for easy replay with the playlog utility.

  • SFTP and SCP support for file upload

  • Support for SSH exec commands

  • Logging of direct-tcp connection attempts (ssh proxying)

  • Forward SMTP connections to SMTP Honeypot (e.g. mailoney)

  • JSON logging for easy processing in log management solutions

Installation

There are three ways to install Cowrie: pip, Docker, and a git checkout. For your first honeypot, pip and Docker are the easiest paths. Use a git checkout for development or advanced scenarios where you want to modify Cowrie itself. Full instructions for all three are in the installation guide.

Docker

Docker images are available on Docker Hub.

  • To get started quickly and give Cowrie a try, run:

    $ docker run -p 2222:2222 cowrie/cowrie:latest
    $ ssh -p 2222 root@localhost
  • To just make it locally, run:

    $ make docker-build

PyPI

Cowrie is available on PyPI. To install it into a virtual environment and start it:

$ mkdir my-honeypot && cd my-honeypot
$ python3 -m venv cowrie-env
$ source cowrie-env/bin/activate
(cowrie-env) $ pip install cowrie
(cowrie-env) $ cowrie init
(cowrie-env) $ cowrie start

cowrie init writes the configuration file etc/cowrie.cfg in the current directory; logs and downloads land under var/.

Requirements

Software required to run locally:

  • Python 3.11+

  • python-virtualenv

Files of interest:

  • etc/cowrie.cfg - Cowrie’s configuration file (operator-owned). Created by cowrie init.

  • src/cowrie/data/etc/cowrie.cfg.dist - bundled defaults, edit your etc/cowrie.cfg instead

  • etc/userdb.txt - credentials to access the honeypot

  • src/cowrie/data/fs.pickle - fake filesystem; carries both metadata (path, uid, gid, size, mode) and the embedded contents (A_CONTENTS bytes) for the small files attackers commonly cat. Edit via fsctl; rebuild via make build-fs-pickle.

  • src/cowrie/data/txtcmds/ - output for simple fake commands

  • var/log/cowrie/cowrie.json - audit output in JSON format

  • var/log/cowrie/cowrie.log - log/debug output

  • var/lib/cowrie/tty/ - session logs, replayable with the playlog utility.

  • var/lib/cowrie/downloads/ - files transferred from the attacker to the honeypot are stored here

Commands

  • cowrie - start, stop and restart Cowrie

  • fsctl - modify the fake filesystem

  • createfs - create your own fake filesystem

  • playlog - utility to replay session logs

  • asciinema - turn Cowrie logs into asciinema files

Contributors

Many people have contributed to Cowrie over the years. Special thanks to:

  • Upi Tamminen (desaster) for all his work developing Kippo on which Cowrie was based

  • Dave Germiquet (davegermiquet) for TFTP support, unit tests, new process handling

  • Olivier Bilodeau (obilodeau) for Telnet support

  • Ivan Korolev (fe7ch) for many improvements over the years.

  • Florian Pelgrim (craneworks) for his work on code cleanup and Docker.

  • Guilherme Borges (sgtpepperpt) for SSH and telnet proxy (GSoC 2019)

  • And many many others.

Metadata

Release files for cowrie 3.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cowrie 3.1.1
File Size Uploaded
cowrie-3.1.1.tar.gz 820.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for cowrie 3.1.1
File Interpreter ABI Platform
cowrie-3.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 1.8 MB

Release files / cowrie-3.1.1.tar.gz

Download URL cowrie-3.1.1.tar.gz
Size 820.0 kB
Tags Source
SHA-256 checksum
How to use checksums
ab0f776021eec98146a681debb5b15916659090f8914cfd0b683d528fead1932
BLAKE2b-256 checksum
How to use checksums
11ebdfa5113cab69c27b952feb3eba31d676936083e054125958401e85337be6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release files / cowrie-3.1.1-py3-none-any.whl

Download URL cowrie-3.1.1-py3-none-any.whl
Size 933.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3ca9baa375a231daf60783aa6d3f90cee3d8a28189c2d5a7b752d2efb12a8f2c
BLAKE2b-256 checksum
How to use checksums
9b34609daa8bf213eaa62e8daf69f71b1a586ba904d17ba86d094a0a15360472
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

3.1.1 This release

2 release files

3.1.0

2 release files

3.0.15

2 release files

3.0.14

2 release files

3.0.13

2 release files

3.0.10

2 release files

3.0.0

2 release files

2.9.0

2 release files

2.8.1

2 release files

2.8.0

2 release files

2.7.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page