Back to articles
Technology Insight

Building an AI Botnet Monitoring Honeypot Using Cowrie and Grafana on Budget Cloud VPS

May 27, 2026

Introduction: The Escalating Threat of AI-Driven Botnets

The cybersecurity landscape is undergoing a massive paradigm shift. As artificial intelligence becomes more accessible, threat actors are no longer relying solely on static, predictable scripts to scan and compromise infrastructure. Today, we are witnessing the rise of AI-driven botnets—automated networks of compromised devices that leverage machine learning algorithms to adapt their brute-force tactics, evade traditional Intrusion Detection Systems (IDS), and identify vulnerabilities with unprecedented speed.

For enterprise defenders and security researchers, staying ahead of these adaptive threats requires active defense mechanisms. One of the most effective ways to study adversary behavior without risking production environments is deploying a Honeypot. A honeypot acts as a decoy system designed to lure attackers, allowing you to log their keystrokes, capture their malware payloads, and analyze their tactics, techniques, and procedures (TTPs).

In this technical guide, we will walk through how to build an enterprise-grade threat intelligence system by deploying Cowrie (an SSH/Telnet honeypot) and visualizing the attack vectors using Grafana. Best of all, we will architect this entire solution to run efficiently on a budget Cloud VPS, proving that robust security monitoring does not require an enterprise-level budget.


System Architecture Overview

Before diving into the configuration, it is essential to understand how the components interact. Our objective is to create an isolated environment that looks like a vulnerable Linux server to an automated botnet, while maintaining strict monitoring and reporting internally.

  • Cloud VPS (The Host): A low-cost virtual private server (e.g., 1-2 vCPUs, 2GB RAM) running Ubuntu Server. It hosts our containerized infrastructure.
  • Cowrie Honeypot: A medium-to-high interaction honeypot configured to mimic an SSH and Telnet server. It logs brute-force attempts, session interactions, and downloaded files.
  • Prometheus / Promtail & Loki Stack: The data ingestion pipeline that collects raw JSON logs from Cowrie, parses them, and indexes them for quick querying.
  • Grafana: The visualization layer that transforms raw log metrics into actionable, real-time security dashboards.
Security Note: It is critical to change your actual VPS management SSH port from 22 to a custom port (e.g., 2222) before deploying Cowrie. Cowrie will occupy port 22 to intercept the automated botnet traffic.

Step 1: Preparing the Cloud VPS Environment

First, access your budget cloud server via SSH and update the core system packages to ensure stability and security. Run the following commands:

sudo apt update && sudo apt upgrade -y
sudo apt install curl git docker.io docker-compose -y

Next, we must reconfigure the host's native SSH daemon so it does not conflict with our honeypot. Edit the SSH configuration file:

sudo nano /etc/ssh/sshd_config

Find the line #Port 22, uncomment it, and change it to a non-standard port:

Port 22345

Save the file, restart the SSH service, and verify you can connect via the new port before proceeding:

sudo systemctl restart sshd

Step 2: Deploying Cowrie via Docker Compose

Using Docker simplifies deployment and adds a layer of isolation between the honeypot container and your host system. Create a dedicated directory for your security stack:

mkdir -p ~/cyber-honeypot/cowrie-data
cd ~/cyber-honeypot

Create a docker-compose.yml file to orchestrate Cowrie along with the logging driver infrastructure. Below is a structured template for deployment:version: '3' services: cowrie: image: cowrie/cowrie:latest container_name: cowrie_honeypot ports: - "22:2222" - "23:2223" volumes: - ./cowrie-data:/cowrie/cowrie-git/var/log/cowrie restart: always

Launch the honeypot in detached mode:

sudo docker-compose up -d

At this point, any automated AI botnet scanning the standard SSH port (22) or Telnet port (23) on your VPS IP address will be seamlessly routed into the Cowrie honeypot environment.


Step 3: Setting Up the Log Analytics Pipeline (Loki & Promtail)

Cowrie generates detailed JSON logs for every interaction, located in ./cowrie-data/cowrie.json. To visualize this data dynamically, we need Grafana Loki to index the logs and Promtail to ship them.

Add the Loki and Promtail configurations to your docker-compose.yml file to create a unified stack. Configure Promtail to scrape the cowrie.json file, extracting key fields such as the attacker's IP address, input commands, and username/password combinations used during brute-force attacks.


Step 4: Crafting the Grafana Threat Intelligence Dashboard

With logs flowing into Loki, deploy Grafana by adding it to your Docker environment or accessing a standalone instance. Once logged into Grafana, add Loki as your primary data source.

To build an effective monitoring dashboard for AI botnets, you should create panels using LogQL (Loki Query Language) to track the following Key Performance Indicators (KPIs):

  1. Total Attack Volume: A real-time counter showing the number of connection attempts per hour. AI botnets often exhibit distinct spike patterns compared to traditional scanners.
  2. Top Attacking IP Addresses & Geographic Origin: Use a GeoIP plugin to map where the automated attacks are originating.
  3. Common Credentials Targeted: A horizontal bar chart visualizing the most frequently used username and password combinations. This reveals what types of enterprise IoT or cloud infrastructure the botnets are currently hunting for.
  4. Executed Command Stream: A terminal-style panel listing the exact shell commands executed by the botnet once it gains "access" to the honeypot. This allows you to witness automated script injections in real time.
Insight: Because AI botnets often analyze responses to optimize their secondary payloads, watching the command stream panels reveals how fast the automation shifts strategies when encountering specific environment setups.

Conclusion & Best Practices for Maintenance

Deploying a Cowrie and Grafana honeypot transforms a passive, low-cost VPS into an active intelligence-gathering asset. By monitoring these controlled environments, security teams gain deep insights into the evolving methodologies of AI-powered botnets without breaking the bank.

To ensure your honeypot remains effective and secure over time, observe these operational best practices:

  • Log Rotation: AI botnets can generate gigabytes of log data within days. Implement strict log rotation policies on your cowrie.json files to avoid exhausting your budget VPS disk space.
  • Payload Isolation: Periodically audit the dl/ directory inside your Cowrie data volume. This is where the honeypot saves binary payloads and malware downloaded by the botnets. Treat these files as highly dangerous and analyze them only in isolated malware sandboxes.
  • Continuous Adaptation: Update your Cowrie configuration profiles regularly. As AI botnets grow smarter, they can detect generic honeypot signatures. Modifying the simulated OS architecture details keeps the illusion intact.

By leveraging open-source tools and affordable cloud infrastructure, proactive threat intelligence is no longer exclusive to Fortune 500 companies. Start building your honeypot today and see what is truly knocking at your network's digital door.

Building an AI Botnet Monitoring Honeypot Using Cowrie and Grafana on Budget Cloud VPS | DPTCloud