README.rst
January 20, 2019 ยท View on GitHub
Cowrie
|travis|_ |circleci|_ |codecov|_
Welcome to the Cowrie GitHub repository
This is the official repository for the Cowrie SSH and Telnet Honeypot effort.
What is Cowrie
Cowrie is a medium interaction SSH and Telnet honeypot designed to log brute force attacks and the shell interaction performed by the attacker. Cowrie also functions as an SSH and telnet proxy to observe attacker behavior to another system.
Cowrie <http://github.com/cowrie/cowrie/>_ is maintained by Michel Oosterhof.
Documentation
The Documentation can be found here <https://cowrie.readthedocs.io/en/latest/index.html>_.
Slack
You can join the Cowrie community at the following Slack workspace <http://bit.ly/cowrieslack>_.
Features
-
Choose to run as an emulated shell (default):
- Fake filesystem with the ability to add/remove files. A full fake filesystem resembling a Debian 5.0 installation is included
- Possibility of adding fake file contents so the attacker can
catfiles such as/etc/passwd. Only minimal file contents are included - Cowrie saves files downloaded with wget/curl or uploaded with SFTP and scp for later inspection
-
Or proxy SSH and telnet to another system
For both settings:
- Session logs are stored in an
UML Compatible <http://user-mode-linux.sourceforge.net/>_ format for easy replay with thebin/playlogutility. - SFTP and SCP support for file upload
- Support for SSH exec commands
- Logging of direct-tcp connection attempts (ssh proxying)
- Forward SMTP connections to SMTP Honeypot (e.g.
mailoney <https://github.com/awhitehatter/mailoney>_) - JSON logging for easy processing in log management solutions
Docker
Docker versions are available.
-
To get started quickly and give Cowrie a try, run::
docker run -p 2222:2222 cowrie/cowrie ssh -p 2222 root@localhost
-
On Docker Hub: https://hub.docker.com/r/cowrie/cowrie
-
Or get the Dockerfile directly at https://github.com/cowrie/docker-cowrie
Requirements
Software required:
- Python 3.5+ (Python 2.7 supported for now but we recommend to upgrade)
- python-virtualenv
For Python dependencies, see requirements.txt <https://github.com/cowrie/cowrie/blob/master/requirements.txt>_.
Files of interest:
etc/cowrie.cfg- Cowrie's configuration file. Default values can be found inetc/cowrie.cfg.dist <https://github.com/cowrie/cowrie/blob/master/etc/cowrie.cfg.dist>_.share/cowrie/fs.pickle- fake filesystemetc/userdb.txt- credentials to access the honeypothoneyfs/ <https://github.com/cowrie/cowrie/tree/master/honeyfs>_ - file contents for the fake filesystem - feel free to copy a real system here or usebin/fsctlhoneyfs/etc/issue.net- pre-login bannerhoneyfs/etc/motd <https://github.com/cowrie/cowrie/blob/master/honeyfs/etc/issue>_ - post-login bannervar/log/cowrie/cowrie.json- transaction output in JSON formatvar/log/cowrie/cowrie.log- log/debug outputvar/lib/cowrie/tty/- session logs, replayable with thebin/playlogutility.var/lib/cowrie/downloads/- files transferred from the attacker to the honeypot are stored hereshare/cowrie/txtcmds/ <https://github.com/cowrie/cowrie/tree/master/share/cowrie/txtcmds>_ - file contents for simple fake commandsbin/createfs <https://github.com/cowrie/cowrie/blob/master/bin/createfs>_ - used to create the fake filesystembin/playlog <https://github.com/cowrie/cowrie/blob/master/bin/playlog>_ - utility to replay session logs
I have some questions!
Please visit the Slack workspace <http://bit.ly/cowrieslack>_ and join the #questions channel.
Contributors
Many people have contributed to Cowrie over the years. Special thanks to:
- Upi Tamminen (desaster) for all his work developing Kippo on which Cowrie was based
- Dave Germiquet (davegermiquet) for TFTP support, unit tests, new process handling
- Olivier Bilodeau (obilodeau) for Telnet support
- Ivan Korolev (fe7ch) for many improvements over the years.
- Florian Pelgrim (craneworks) for his work on code cleanup and Docker.
- Guilherme Borges (sgtpepperpt) for SSH and telnet proxy (GSoC 2019)
- And many many others.
.. |travis| image:: https://travis-ci.com/cowrie/cowrie.svg?branch=master .. _travis: https://travis-ci.com/cowrie/cowrie
.. |circleci| image:: https://circleci.com/gh/cowrie/cowrie.svg?style=svg .. _circleci: https://circleci.com/gh/cowrie/cowrie
.. |codecov| image:: https://codecov.io/gh/cowrie/cowrie/branch/master/graph/badge.svg .. _codecov: https://codecov.io/gh/cowrie/cowrie