How I Set Up a Cowrie Honeypot to Capture Real SSH Attacks

Learn how to set up a Cowrie honeypot on Ubuntu to capture real SSH attacks and analyze intrusion tactics, correlating data with MITRE ATT&CK. Get security tips, Cowrie installation, data capture and analysis, and how Q2BSTUDIO can support your cybersecurity projects

jueves, 14 de agosto de 2025 • 3 min read • Q2BSTUDIO Team

Artificial-Intelligence-

How I set up a Cowrie honeypot to capture real SSH attacks

This article documents in a practical way the deployment of a Cowrie honeypot on Ubuntu to capture and analyze in real time the behavior of SSH intrusions. The lab covers everything from environment preparation and port forwarding to logging attacker actions and correlating them with MITRE ATT&CK techniques.

Environment preparation: the choice of an Ubuntu VM is described, the network configuration needed to expose the simulated SSH service, and the security considerations to isolate the honeypot from the rest of the production infrastructure. Minimal firewall rules and the use of NAT and port forwarding to channel SSH traffic to the honeypot are detailed.

Installation and configuration of Cowrie: steps to install dependencies, clone the Cowrie repository, adjust the configuration file to simulate systems and services, and enable detailed session capture. It explains how to customize banners, fake credentials, and emulated file systems to increase the fidelity of malicious interactions.

Capture and logging: Cowrie stores commands, file transfers, and complete sessions. It shows how to centralize logs in JSON format, enable remote syslog, or send events to a SIEM. The large amount of data collected allows analyzing tactics, techniques, and procedures of real attackers.

Analysis with Python and regular expressions: use of Python scripts to parse JSON logs and extract indicators such as IP addresses, executed commands, brute force patterns, and file hashes. Examples of regular expressions are included to identify enumeration, exfiltration, and malware execution attempts.

Mapping to MITRE ATT&CK: each observed action is mapped to MITRE ATT&CK techniques to understand the attack lifecycle, from initial enumeration and credential dumping to persistence and evasion attempts. This approach allows prioritizing mitigations and enriching detection rules in a SOC.

Data visualization: generation of dashboards and charts to show temporal trends, attacker geolocation, most frequent commands, and entry vectors. Tools such as Power BI for executive reports and open source solutions for continuous monitoring are recommended.

Lessons learned and recommended practices: network segmentation, real-time monitoring, use of signature- and behavior-based alerts, and constant updating of the honeypot to simulate new versions of services. It also discusses how to prevent the honeypot from being a springboard for attacks against third parties.

Project as a professional portfolio: this lab is ideal for threat hunters, SOC analysts, and cybersecurity developers looking to demonstrate practical skills in detection, analysis, and response. Documenting the methodology and results is a valuable asset for interviews and technical portfolios.

About Q2BSTUDIO: at Q2BSTUDIO we are a custom software and application development company specialized in artificial intelligence, cybersecurity, and cloud solutions. We offer AWS and Azure cloud services, custom software implementation, custom applications, and business intelligence service projects. Our team combines experience in AI for businesses, AI agents, and Power BI integration development to transform data into decisions.

How Q2BSTUDIO can help: we offer consulting to deploy honeypots as part of threat intelligence programs, creation of analysis pipelines using Python and Power BI visualizations, and design of security controls to mitigate techniques identified in MITRE ATT&CK. Our services include custom software development, artificial intelligence integration, and managed support in AWS and Azure cloud services.

Keywords to improve positioning: custom applications, custom software, artificial intelligence, cybersecurity, AWS and Azure cloud services, business intelligence services, AI for businesses, AI agents, Power BI.

Conclusion: deploying a Cowrie honeypot is an effective and educational way to capture real SSH attacks and turn that intelligence into defensive improvements. If you are looking for support for cybersecurity projects, custom development, or artificial intelligence solutions, contact Q2BSTUDIO to design a strategy tailored to your needs.

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.