Tech riderRev. 2 Oct 2026
- 1Runs onLinux, self-hosted
- 2CostsFree plan
- 3Deployment modelself-hosted
- 4Decoy scopemulti-layer
- 5Credential luresYes
5 lines stated Written from the maker's own pages: cowrie.org

Overview
Cowrie is ranked #6 of 18 in honeypot software on Specifiction. It runs on Linux, Self-hosted. There is a free plan.
Cowrie plans and pricing
All plansCompared on honeypot software
- Free plan
- Yescowrie.org
- Deployment model
- self-hostedcowrie.org
- Decoy scope
- multi-layercowrie.org
- Credential lures
- Yescowrie.org
Facts
- What it does
- Cowrie is a medium- to high-interaction SSH and Telnet honeypot designed to log brute-force attacks and attackers’ shell activity.docs.cowrie.org · 2 Oct 2026
- Emulated shell
- Its default shell mode emulates a UNIX system in Python with a fake filesystem and does not run attackers’ commands on the real host.cowrie.org · 2 Oct 2026
- Proxy mode
- Proxy mode forwards SSH and Telnet sessions to another system while monitoring attacker behavior.docs.cowrie.org · 2 Oct 2026
- Session recording
- Cowrie records terminal sessions with timing information for later replay using its playlog utility.cowrie.org · 2 Oct 2026
- Malware capture
- Cowrie saves files fetched with wget or curl and files uploaded with SFTP or SCP for later inspection.docs.cowrie.org · 2 Oct 2026
- Logging
- Cowrie logs attacker activity as JSON, including logins, commands, downloads, TCP forwards and session metadata.cowrie.org · 2 Oct 2026
- Integrations
- Output plugins include Elasticsearch, Splunk, Microsoft Sentinel, MISP, VirusTotal, Slack, Discord, MySQL, PostgreSQL, SQLite, MongoDB, Graylog, Kafka, Prometheus, Datadog and Amazon S3.cowrie.org · 2 Oct 2026
- LLM mode
- An experimental LLM backend can generate dynamic shell responses and maintain conversation context across a session.docs.cowrie.org · 2 Oct 2026
- Deployment
- Cowrie can be installed using pip, Docker or a Git checkout, and its documentation lists Python 3.11+ and python-virtualenv as local requirements.docs.cowrie.org · 2 Oct 2026
- Security boundary
- The feature page says the emulated shell is safe to expose because commands run in a fake filesystem and do not touch the real host.cowrie.org · 2 Oct 2026
- License and history
- Cowrie is free and open source under a BSD license and began in 2014 as a fork of the Kippo honeypot.cowrie.org · 2 Oct 2026
- Who maintains it
- Cowrie is maintained by volunteers, and the project credits creator and maintainer Michel Oosterhof.cowrie.org · 2 Oct 2026
- Intended users
- The project says it is used by security researchers, CERTs and defenders around the world.cowrie.org · 2 Oct 2026
- Support
- The project links users to community Slack and Discord channels.cowrie.org · 2 Oct 2026
Company
- Founded
- 2014cowrie.org · 23 Sept 2026
Best Cowrie alternatives
See all 17 All accessCh 01 OpenCanary Free planLinuxMac Free to start7.3 All accessCh 02 Beelzebub Free planFree trialAPI Free to start7.2 All accessCh 03 Canarytokens Free planAndroidiOS Free to start7.2 All accessCh 04 Honeyd Free planLinuxself-hosted Free to start7.0 All accessCh 05 T-Pot Free planLinuxMac Free to start7.0 All accessCh 07 Honeytrap Free planLinuxself-hosted Free to start6.9
Where it ranks on Specifiction
- Best Honeypot Software in 2026#6 of 18
Is Cowrie yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- docs.cowrie.org/en/stable/README.html· checked 2 Oct 2026
- cowrie.org/features/· checked 2 Oct 2026
- cowrie.org· checked 2 Oct 2026
- cowrie.org/integrations/· checked 2 Oct 2026
- cowrie.org/about/· checked 2 Oct 2026


