Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Deployed SSH and HTTP honeypot on my Raspberry Pi Zero W and want to share my process

0
Medium
Published: 08/20/2026 (08/20/2026, 18:14:10 UTC)
Source: Reddit Cybersecurity

Description

This content describes a personal project involving the deployment of SSH and HTTP honeypots (Cowrie and Krawl) on a Raspberry Pi Zero W to simulate attacks and observe malicious activity. The author shares their installation experience, including challenges with architecture compatibility and software dependencies, and invites feedback and ideas for further projects.

Reddit Discussion

r/cybersecurity·posted by u/TrickyWinter7847
00

I set up Cowrie SSH and Krawl web honeypots on my Raspberry Pi Zero W and simulated an attack using my Kali Linux machine, then observed the logs. This is one of the projects I did this summer to gain experience from the defensive side of cybersecurity and I would love to hear your thoughts about it.

I used good old Raspberry Pi Zero W with ARMv6 architecture (which complicated the process little bit).

I installed both honeypots. Then I booted my Kali Linux machine and ran simulated brute-force attack against SSH honeypot and scrutinised the filesystem. In case of the fake web server I ran Nmap and Gobuster scans and observed every malicious activity in recorded logs.

Cowrie installation went just fine with Python virtual environment and Pip. But Krawl's primary installation method was via Docker. And... Docker no longer supports the architecture of Pi Zero W. So I had to stick with secondary method, via Uvicorn. Which wasn't too bad, but package "uvloop" was causing problems, so I tried to remove it from the requirements. It seemed to install just fine and Krawl was running. Logs were recorded, dashboard was running, but didn't show a lot of data. It showed captured credentials and attacking IPs, but not all the additional information it should that you see in other videos or demonstrations. But Krawl logs were being recorded just fine and even Gobuster fuzzing got flagged as suspicious. Anyway, I left it at that. Maybe someone here had similar experience.

I like to do these simple projects to gain more experience under my belt.

Do you have a project idea what can a cybersecurity enthusiast like me do next?

Link to the Medium post about the honeypots deployment:

https://medium.com/@ivandano77/deploying-cowrie-krawl-honeypots-on-raspberry-pi-zero-w-f5e96327367b?sharedUserId=ivandano77

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/20/2026, 18:22:09 UTC

Technical Analysis

The author deployed Cowrie SSH and Krawl HTTP honeypots on a Raspberry Pi Zero W with ARMv6 architecture. They simulated brute-force SSH attacks and web scans using Kali Linux, capturing logs and observing attacker behavior. Installation of Cowrie was straightforward using Python virtual environments, but Krawl required a workaround due to Docker incompatibility with the Pi Zero W architecture. The alternative Uvicorn method worked with some package adjustments, though the dashboard showed limited data. The project was conducted for learning and defensive experience, not as a report of a vulnerability or active threat.

Potential Impact

There is no direct security impact or vulnerability reported. The content is an experiential report on honeypot deployment and testing, with no indication of exploitation or risk to others.

Defensive Guidance

No mitigation is required as this is not a vulnerability or active threat. The content is informational and relates to a personal cybersecurity learning project.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a8745cbacd9273b49fa80b2

Added to database: 08/20/2026, 18:22:03 UTC

Last enriched: 08/20/2026, 18:22:09 UTC

Last updated: 08/20/2026, 20:51:58 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses