Library / Open software
Open software
Cowrie
SSH and Telnet honeypot that records login attempts and attacker sessions.
HoneypotNetwork
Critical reading · Sep 15, 2026
What the source supports
The repository documents SSH/Telnet login and session capture.
Question for evaluation
What share of sessions leads to useful investigation, and at what operational cost?
This note is bounded by the material shown under “Review depth”. It is not an independent test.
Evidence limits
Commands observed in a honeypot do not represent all attackers or prove detection effectiveness.
Sources and provenance
- Cowrie
repository-metadata · 2026-09-15
Reviewed: 2026-09-15. This record may change when new evidence is found.
RIS · BibTeX
Related resources
Paper2024
Review: AbstractCritical readingPresents a language-model terminal honeypot architecture and describes a field evaluation.
NetworkHoneypot
Paper2024
Review: AbstractCritical readingPresents an interactive honeypot using a language model fine-tuned with attacker command data.
NetworkHoneypot
Dataset or lab2020
Review: Public pageCritical readingCowrie honeypot session data from a distributed deployment, according to Zenodo.
NetworkHoneypot