Deployed SSH and HTTP honeypot on my Raspberry Pi Zero W and want to share my process
This content describes a personal project involving the deployment of SSH and HTTP honeypots (Cowrie and Krawl) on a Raspberry Pi Zero W to simulate attacks and observe malicious activity. The author shares their installation experience, including challenges with architecture compatibility and software dependencies, and invites feedback and ideas for further projects.
AI Analysis
Technical Summary
The author deployed Cowrie SSH and Krawl HTTP honeypots on a Raspberry Pi Zero W with ARMv6 architecture. They simulated brute-force SSH attacks and web scans using Kali Linux, capturing logs and observing attacker behavior. Installation of Cowrie was straightforward using Python virtual environments, but Krawl required a workaround due to Docker incompatibility with the Pi Zero W architecture. The alternative Uvicorn method worked with some package adjustments, though the dashboard showed limited data. The project was conducted for learning and defensive experience, not as a report of a vulnerability or active threat.
Potential Impact
There is no direct security impact or vulnerability reported. The content is an experiential report on honeypot deployment and testing, with no indication of exploitation or risk to others.
Mitigation Recommendations
No mitigation is required as this is not a vulnerability or active threat. The content is informational and relates to a personal cybersecurity learning project.
Deployed SSH and HTTP honeypot on my Raspberry Pi Zero W and want to share my process
Description
This content describes a personal project involving the deployment of SSH and HTTP honeypots (Cowrie and Krawl) on a Raspberry Pi Zero W to simulate attacks and observe malicious activity. The author shares their installation experience, including challenges with architecture compatibility and software dependencies, and invites feedback and ideas for further projects.
Reddit Discussion
I set up Cowrie SSH and Krawl web honeypots on my Raspberry Pi Zero W and simulated an attack using my Kali Linux machine, then observed the logs. This is one of the projects I did this summer to gain experience from the defensive side of cybersecurity and I would love to hear your thoughts about it.
I used good old Raspberry Pi Zero W with ARMv6 architecture (which complicated the process little bit).
I installed both honeypots. Then I booted my Kali Linux machine and ran simulated brute-force attack against SSH honeypot and scrutinised the filesystem. In case of the fake web server I ran Nmap and Gobuster scans and observed every malicious activity in recorded logs.
Cowrie installation went just fine with Python virtual environment and Pip. But Krawl's primary installation method was via Docker. And... Docker no longer supports the architecture of Pi Zero W. So I had to stick with secondary method, via Uvicorn. Which wasn't too bad, but package "uvloop" was causing problems, so I tried to remove it from the requirements. It seemed to install just fine and Krawl was running. Logs were recorded, dashboard was running, but didn't show a lot of data. It showed captured credentials and attacking IPs, but not all the additional information it should that you see in other videos or demonstrations. But Krawl logs were being recorded just fine and even Gobuster fuzzing got flagged as suspicious. Anyway, I left it at that. Maybe someone here had similar experience.
I like to do these simple projects to gain more experience under my belt.
Do you have a project idea what can a cybersecurity enthusiast like me do next?
Link to the Medium post about the honeypots deployment:
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The author deployed Cowrie SSH and Krawl HTTP honeypots on a Raspberry Pi Zero W with ARMv6 architecture. They simulated brute-force SSH attacks and web scans using Kali Linux, capturing logs and observing attacker behavior. Installation of Cowrie was straightforward using Python virtual environments, but Krawl required a workaround due to Docker incompatibility with the Pi Zero W architecture. The alternative Uvicorn method worked with some package adjustments, though the dashboard showed limited data. The project was conducted for learning and defensive experience, not as a report of a vulnerability or active threat.
Potential Impact
There is no direct security impact or vulnerability reported. The content is an experiential report on honeypot deployment and testing, with no indication of exploitation or risk to others.
Defensive Guidance
No mitigation is required as this is not a vulnerability or active threat. The content is informational and relates to a personal cybersecurity learning project.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a8745cbacd9273b49fa80b2
Added to database: 08/20/2026, 18:22:03 UTC
Last enriched: 08/20/2026, 18:22:09 UTC
Last updated: 08/20/2026, 20:51:58 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.