Open software

Cowrie

SSH and Telnet honeypot that records login attempts and attacker sessions.

HoneypotNetwork

Critical reading · Sep 15, 2026

What the source supports

The repository documents SSH/Telnet login and session capture.

Question for evaluation

What share of sessions leads to useful investigation, and at what operational cost?

This note is bounded by the material shown under “Review depth”. It is not an independent test.

Evidence limits

Commands observed in a honeypot do not represent all attackers or prove detection effectiveness.

Sources and provenance

  1. Cowrie
    repository-metadata · 2026-09-15

Reviewed: 2026-09-15. This record may change when new evidence is found.

RIS · BibTeX

Related resources

Dataset or lab2020

CyberLab Honeynet Dataset

Review: Public pageCritical reading

Cowrie honeypot session data from a distributed deployment, according to Zenodo.

NetworkHoneypot