cowrie2neo is a specialized tool designed to parse log files generated by Cowrie honeypots and import the extracted data into Neo4j graph databases. The tool processes honeypot interaction logs to transform raw log data into structured formats suitable for graph database storage. It enables security researchers and analysts to leverage Neo4j's graph capabilities for examining attack patterns, relationships between attackers, and behavioral analysis of malicious activities captured by Cowrie honeypots. The tool facilitates the conversion of linear log data into interconnected graph structures, allowing for advanced querying and visualization of honeypot data. This transformation enables users to identify attack chains, correlate events, and perform complex analysis on honeypot interactions that would be difficult to achieve with traditional log analysis methods. cowrie2neo supports the integration of honeypot data with Neo4j's ecosystem, enabling users to apply graph algorithms and create custom visualizations for threat intelligence and security research purposes.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
An Apache 2 based honeypot with detection capabilities specifically designed to identify and analyze Struts CVE-2017-5638 exploitation attempts.
A Docker-based honeypot network implementation featuring cowrie and dionaea honeypots with centralized event collection, geolocation enrichment, and real-time attack visualization.
A low-interaction SSH authentication logging honeypot that logs all authentication attempts in JSON format.
A web-based visualization tool that displays statistics and generates charts from Shockpot honeypot data stored in PostgreSQL databases.
A serverless application that creates and monitors fake HTTP endpoints as honeytokens to detect attackers, malicious insiders, and automated threats.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.