Back to articles
Technology Insight

Building a Modern Honeypot: Using Cowrie to Monitor and Analyze SSH Attacks on VPS

June 3, 2026

Introduction to Proactive Cyber Defense

In the modern cybersecurity landscape, reactive defense is no longer sufficient. Organizations and system administrators often find themselves playing a perpetual game of catch-up, patching vulnerabilities only after they have been actively exploited. To truly secure an infrastructure, one must understand the tactics, techniques, and procedures (TTPs) utilized by threat actors. This is where honeypots come into play.

A honeypot is a decoy system designed to mimic a legitimate digital asset, purposefully left vulnerable to lure attackers. By deploying a honeypot, you create a controlled environment where malicious activities can be safely observed, logged, and analyzed without risking production data. This guide focuses on Cowrie, a highly sophisticated, medium-to-high interaction SSH and Telnet honeypot designed to log brute-force attacks and shell interaction performed by the attacker.

Why Choose Cowrie for SSH Monitoring?

SSH (Secure Shell) is one of the most frequently targeted services on Virtual Private Servers (VPS). Automated bots scan the IPv4 address space continuously, looking for weak credentials to enlist servers into botnets or deploy crypto-miners. Cowrie provides an elegant solution to observe these attacks in real-time.

Unlike simple low-interaction honeypots that merely log connection attempts, Cowrie offers an emulated UNIX environment. When an attacker successfully guesses a fake password, they are granted access to a simulated shell. Cowrie then records:

  • Every single keystroke and command executed by the intruder.
  • Files attempted to be downloaded via wget or curl.
  • The exact IP addresses, usernames, and passwords used in the brute-force phase.
  • Session replays, allowing defenders to watch the attack unfold frame-by-frame.

Step-by-Step Architecture and Deployment Strategy

Deploying Cowrie requires a strategic approach. Because Cowrie emulates an SSH server, it typically runs on port 22. However, the host server\'s actual SSH service must still be accessible to the administrator. Therefore, a port-shifting strategy is essential.

Phase 1: Preparing the Host Server

Before installing Cowrie, you must move your real SSH port to a non-standard port (e.g., port 2222). This ensures that you do not accidentally lock yourself out of your VPS and leaves port 22 completely free for the honeypot.

  1. Edit the SSH configuration file using sudo nano /etc/ssh/sshd_config.
  2. Locate the Port 22 directive and change it to Port 2222.
  3. Update your firewall rules to allow traffic on the new port.
  4. Restart the SSH service using sudo systemctl restart sshd.
Warning: Always test your new SSH connection in a separate terminal window before closing your current session to prevent permanent lockout.

Phase 2: Installing Dependencies and Cowrie

Cowrie is written in Python and operates best within an isolated environment. It should never be run under the root user account to prevent potential container escape vulnerabilities from compromising the actual host machine.

First, create a dedicated, unprivileged system user:

sudo adduser --disabled-password cowrie
sudo su - cowrie

Next, clone the official repository and set up a virtual environment to manage dependencies securely:

git clone [http://github.com/cowrie/cowrie.git](http://github.com/cowrie/cowrie.git)
cd cowrie
python3 -m venv cowrie-env
source cowrie-env/bin/activate
pip install --upgrade pip
pip install -r requirements.txt

Phase 3: Configuration and Customization

Cowrie\'s default settings are highly functional, but customization makes the trap far more convincing. Copy the default configuration file to create your local template:

cp cowrie.cfg.dist cowrie.cfg

Within cowrie.cfg, administrators can modify the hostname (e.g., naming it mail-server-01 or prod-db to attract deeper inspection), fake operating system versions, and simulated file systems. To make the honeypot realistic, edit the data/userdb.txt file to define which username and password combinations will successfully log the attacker in.

Analyzing the Harvested Intelligence

Once Cowrie is activated and traffic is routed to it via port forwarding, logs will begin accumulating almost instantly. Cowrie stores these logs in structured JSON format under the log/cowrie.json directory, making them highly compatible with modern Security Information and Event Management (SIEM) systems.

Decoding the TTY Replays

One of Cowrie\'s most powerful features is its ability to record terminal sessions. Even if an attacker clears their history or uses advanced techniques to hide their tracks, Cowrie saves raw TTY logs. These logs can be replayed using the built-in utility:

bin/playlog log/tty/.log

Watching a live replay provides deep contextual insight into whether the attacker is an automated script looking for low-hanging fruit or a human operator manually inspecting your system architecture.

Malware Analysis and Triage

When attackers attempt to upload malicious binaries or scripts via curl, Cowrie intercepts the download. Instead of executing the file, Cowrie saves it to the var/lib/cowrie/downloads/ directory and calculates its SHA-256 hash. These files can then be uploaded automatically to threat intelligence platforms like VirusTotal to determine if you are dealing with a known strain of malware or a zero-day exploit.

Conclusion and Strategic Takeaways

Deploying a Cowrie honeypot turns a vulnerable VPS into a potent intelligence-gathering asset. By analyzing the automated attack vectors targeting your system, you gain actionable data regarding current botnet activities, active malicious IP pools, and evolving hacking methodologies. Incorporating honeypots into your security posture shifts your organization from a purely defensive stance to an informed, proactive operation capable of anticipating threats before they reach critical business systems.

Building a Modern Honeypot: Using Cowrie to Monitor and Analyze SSH Attacks on VPS | DPTCloud