Cowrie
What is Cowrie
Cowrie is a medium to high interaction SSH and Telnet honeypot designed to log brute force attacks and the shell interaction performed by the attacker. In medium interaction mode (shell) it emulates a UNIX system in Python, in high interaction mode (proxy) it functions as an SSH and telnet proxy to observe attacker behavior on another system. In LLM mode, it uses large language models to generate dynamic responses to attacker commands.
Cowrie is maintained by Michel Oosterhof.
Documentation
The Documentation can be found here.
Slack
You can join the Cowrie community at the following Slack workspace.
Features
- Choose to run as an emulated shell (default):
Fake filesystem with the ability to add/remove files. A full fake filesystem resembling a Debian 5.0 installation is included
Possibility of adding fake file contents so the attacker can cat files such as /etc/passwd. Only minimal file contents are included
Cowrie saves files downloaded with wget/curl or uploaded with SFTP and scp for later inspection
- Or proxy SSH and telnet to another system
Run as a pure telnet and ssh proxy with monitoring
Or let Cowrie manage a pool of QEMU emulated servers to provide the systems to login to
- Or use an LLM backend (experimental):
Use large language models (e.g., OpenAI GPT) to dynamically generate realistic shell responses
Handles any command without predefined responses
Maintains conversation context for consistent sessions
For both settings:
Session logs are stored in a User Mode Linux compatible format for easy replay with the playlog utility.
SFTP and SCP support for file upload
Support for SSH exec commands
Logging of direct-tcp connection attempts (ssh proxying)
Forward SMTP connections to SMTP Honeypot (e.g. mailoney)
JSON logging for easy processing in log management solutions
Installation
There are three ways to install Cowrie: pip, Docker, and a git checkout. For your first honeypot, pip and Docker are the easiest paths. Use a git checkout for development or advanced scenarios where you want to modify Cowrie itself. Full instructions for all three are in the installation guide.
Docker
Docker images are available on Docker Hub.
To get started quickly and give Cowrie a try, run:
$ docker run -p 2222:2222 cowrie/cowrie:latest $ ssh -p 2222 root@localhost
To just make it locally, run:
$ make docker-build
PyPI
Cowrie is available on PyPI. To install it into a virtual environment and start it:
$ mkdir my-honeypot && cd my-honeypot $ python3 -m venv cowrie-env $ source cowrie-env/bin/activate (cowrie-env) $ pip install cowrie (cowrie-env) $ cowrie init (cowrie-env) $ cowrie start
cowrie init writes the configuration file etc/cowrie.cfg in the current directory; logs and downloads land under var/.
Requirements
Software required to run locally:
Python 3.11+
python-virtualenv
Files of interest:
etc/cowrie.cfg - Cowrie’s configuration file (operator-owned). Created by cowrie init.
src/cowrie/data/etc/cowrie.cfg.dist - bundled defaults, edit your etc/cowrie.cfg instead
etc/userdb.txt - credentials to access the honeypot
src/cowrie/data/fs.pickle - fake filesystem; carries both metadata (path, uid, gid, size, mode) and the embedded contents (A_CONTENTS bytes) for the small files attackers commonly cat. Edit via fsctl; rebuild via make build-fs-pickle.
src/cowrie/data/txtcmds/ - output for simple fake commands
var/log/cowrie/cowrie.json - audit output in JSON format
var/log/cowrie/cowrie.log - log/debug output
var/lib/cowrie/tty/ - session logs, replayable with the playlog utility.
var/lib/cowrie/downloads/ - files transferred from the attacker to the honeypot are stored here
Commands
cowrie - start, stop and restart Cowrie
fsctl - modify the fake filesystem
createfs - create your own fake filesystem
playlog - utility to replay session logs
asciinema - turn Cowrie logs into asciinema files
Contributors
Many people have contributed to Cowrie over the years. Special thanks to:
Upi Tamminen (desaster) for all his work developing Kippo on which Cowrie was based
Dave Germiquet (davegermiquet) for TFTP support, unit tests, new process handling
Olivier Bilodeau (obilodeau) for Telnet support
Ivan Korolev (fe7ch) for many improvements over the years.
Florian Pelgrim (craneworks) for his work on code cleanup and Docker.
Guilherme Borges (sgtpepperpt) for SSH and telnet proxy (GSoC 2019)
And many many others.
Metadata
Release files for cowrie 3.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| cowrie-3.1.0.tar.gz | 816.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| cowrie-3.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 1.7 MB
Release files / cowrie-3.1.0.tar.gz
| Download URL | cowrie-3.1.0.tar.gz |
|---|---|
| Size | 816.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1d68aa56967653dc2dce1652601d8cfbf1384a4682cc319debcd74487236f8d6
|
|
BLAKE2b-256 checksum How to use checksums |
01f121e74b1e8fa411dcaaacd12decabf5d31ffd59462959c85ba51abf9e4d6a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / cowrie-3.1.0-py3-none-any.whl
| Download URL | cowrie-3.1.0-py3-none-any.whl |
|---|---|
| Size | 928.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c70b6e065174b7351e58c6fb54637a23f14d0f0e4a471b6fed390d97ba6ef493
|
|
BLAKE2b-256 checksum How to use checksums |
35a7428fa4ddf457f1ca01d9824241a562f9410c23349e0c10a8793278c391ad
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency log