cowrie

Getting started

  • Cowrie
  • Installing Cowrie
  • Frequently asked questions

Configuring the honeypot

  • Changing the Cowrie file system
  • Using the Proxy
  • Backend Pool
  • Analyzing snapshots and downloaded content
  • Using the LLM Backend

Deployment

  • Docker Repository
  • Automatically starting Cowrie with systemd
  • Automatically starting Cowrie with supervisord
  • Using TCP tunneling with Squid

Output integrations

  • How to send Cowrie output to Datadog Log Management
  • How to send Cowrie output to an ELK stack
  • How to send Cowrie output to Graylog
  • How to Send Cowrie Output to Prometheus
  • 1. Create the Docker network
  • 2. Prepare the Prometheus volume and configuration
  • 3. Launch Prometheus on cowrie-net
  • 4. Run Cowrie with Prometheus metrics
  • 5. Run node-exporter (host metrics)
  • 6. Run cAdvisor (container metrics)
  • Run cowrie with prometheus locally
  • How to send Cowrie output to Azure Sentinel
  • How to send Cowrie output to Splunk
  • How to Send Cowrie output to a MySQL or PostgreSQL Database
  • VirusTotal Integration

Reference

  • Output Event Code Reference
  • Event Pipeline Design

Project

  • Contributing Guidelines
  • Release Notes
  • LICENSE
cowrie
  • Search


© Copyright 2014-2025, Michel Oosterhof.

Built with Sphinx using a theme provided by Read the Docs.