Cowrie是一种中等交互式SSH和Telnet蜜罐,用于记录暴力攻击和攻击者执行的shell交互。Cowrie还充当SSH和telnet代理,以观察攻击者对另一个系统的行为。
使用方法:
dockerrun-p2222:2222cowrie/cowriessh-p2222root@localhost文件列表:
etc/cowrie.cfg-Cowrie'sconfigurationfile.Defaultvaluescanbefoundin etc/cowrie.cfg.dist.share/cowrie/fs.pickle-fakefilesystemetc/userdb.txt-credentialstoaccessthehoneypothoneyfs/ -filecontentsforthefakefilesystem-feelfreetocopyarealsystemhereorusebin/fsctlhoneyfs/etc/issue.net-pre-loginbannerhoneyfs/etc/motd -post-loginbannervar/log/cowrie/cowrie.json-transactionoutputinJSONformatvar/log/cowrie/cowrie.log-log/debugoutputvar/lib/cowrie/tty/-sessionlogs,replayablewiththebin/playlogutility.var/lib/cowrie/downloads/-filestransferredfromtheattackertothehoneypotarestoredhereshare/cowrie/txtcmds/ -filecontentsforsimplefakecommandsbin/createfs -usedtocreatethefakefilesystembin/playlog -utilitytoreplaysessionlogs
评论