MCPcopy Create free account

hub / github.com/cowrie/cowrie / functions

Functions2,302 in github.com/cowrie/cowrie

↓ 3 callersMethoddestroy_all_cowrie
(self)
src/backend_pool/libvirt/backend_service.py:216
↓ 3 callersMethoddo_ulimit
(self, key: str = "core", value: int = 0)
src/cowrie/commands/ulimit.py:44
↓ 3 callersMethoddojob
(self, s: bytes)
src/cowrie/commands/base64.py:121
↓ 3 callersFunctiondurationHuman
Turn number of seconds into human readable string
src/cowrie/core/utils.py:37
↓ 3 callersMethoderaseDisplay
(self)
src/cowrie/test/fake_transport.py:173
↓ 3 callersMethoderror
handle any exceptions
src/cowrie/commands/curl.py:459
↓ 3 callersFunctionfile_md5
Return the MD5 hex digest of the file at ``path``. MISP stores ``malware-sample`` attribute values as ``filename|md5``, so MD5 is the hash us
src/cowrie/output/misp.py:28
↓ 3 callersFunctiongenerate_ja4
Generate JA4 fingerprint from TLS Client Hello. Args: tls_version: TLS version number ciphers: List of cipher suite values
src/cowrie/core/fingerprint.py:239
↓ 3 callersFunctiongenerate_ja4h
Generate JA4H fingerprint from HTTP request using FoxIO's logic. Args: method: HTTP method (GET, POST, etc) version: HTTP ve
src/cowrie/core/fingerprint.py:305
↓ 3 callersMethodgetCommand
(name: str)
src/cowrie/commands/yum.py:33
↓ 3 callersMethodgetProtoTransport
Due to protocol nesting differences, we need provide how we grab the proper transport to access underlying SSH information. Meant to
src/cowrie/shell/protocol.py:73
↓ 3 callersFunctionget_int
(data: bytes, length: int = 4)
src/cowrie/ssh_proxy/client_transport.py:19
↓ 3 callersFunctionget_pid_file
Get the path to the PID file (cwd-relative).
src/cowrie/scripts/cowrie.py:28
↓ 3 callersMethodget_variable
Return the value of a shell variable, or None if unset.
src/cowrie/shell/bashparse.py:182
↓ 3 callersMethodgetpwnam
Get passwd entry for username
src/cowrie/shell/pwd.py:90
↓ 3 callersMethodhandle_CTRL_C
(self)
src/cowrie/commands/nc.py:281
↓ 3 callersMethodhelp
(self)
src/cowrie/commands/fs.py:50
↓ 3 callersMethodhelp
(self)
src/cowrie/commands/chpasswd.py:23
↓ 3 callersMethodhelp
(self)
src/cowrie/commands/wc.py:42
↓ 3 callersMethodhelp
(self)
src/cowrie/commands/service.py:91
↓ 3 callersMethodhttp_request
(self, params)
src/cowrie/output/abuseipdb.py:383
↓ 3 callersMethodinitFileSystem
Do this so we can trigger it later. Not all sessions need file system
src/cowrie/shell/server.py:50
↓ 3 callersMethodis_valid_chain
(self, chain: str)
src/cowrie/commands/iptables.py:262
↓ 3 callersMethodislink
Return True if path refers to a directory entry that is a symbolic link.
src/cowrie/shell/fs.py:406
↓ 3 callersMethodlineReceived
Parse a command line with the Lark grammar and run the result.
src/cowrie/shell/honeypot.py:167
↓ 3 callersMethodlogin
(ignored)
src/cowrie/telnet/userauth.py:116
↓ 3 callersMethodloseConnection
(self)
src/cowrie/llm/telnet.py:130
↓ 3 callersFunctionparse_http_request
Parse HTTP request headers for JA4H fingerprinting. Returns a dict with: method, version, headers, cookies, referer, accept_language Ret
src/cowrie/core/fingerprint.py:165
↓ 3 callersFunctionparse_tls_client_hello
Parse a TLS Client Hello packet and extract fields needed for JA4 fingerprinting. Returns a dict with: tls_version, ciphers, extensions, has
src/cowrie/core/fingerprint.py:37
↓ 3 callersMethodpostfile
Send a file to Cuckoo
src/cowrie/output/cuckoo.py:133
↓ 3 callersMethodprint_usage_error
Print usage error message
src/cowrie/commands/sleep.py:29
↓ 3 callersMethodprint_usage_error
Print usage error message
src/cowrie/commands/wget.py:113
↓ 3 callersFunctionprinthelp
(brief=0)
src/cowrie/scripts/playlog.py:82
↓ 3 callersFunctionprinthelp
(verbose=False)
src/cowrie/scripts/asciinema.py:96
↓ 3 callersFunctionreadConfigFile
Build a ConfigParser by stacking layers: 1. Bundled cowrie.cfg.dist from the package (default values). 2. The user files listed in c
src/cowrie/core/config.py:46
↓ 3 callersMethodrequest_interface
(self, initial_setup=False)
src/cowrie/pool_interface/handler.py:68
↓ 3 callersMethodrmdir
(self, path: str)
src/cowrie/shell/fs.py:526
↓ 3 callersMethodscanurl
Check url scan report for a hash
src/cowrie/output/virustotal.py:363
↓ 3 callersMethodschedule_next
(self)
src/cowrie/commands/adduser.py:85
↓ 3 callersMethodsendACK
Send ACKnowledgment packet
src/cowrie/commands/tftp.py:93
↓ 3 callersMethodsendPacket
Override because OpenSSH pads with 0 on KEXINIT
src/cowrie/ssh/transport.py:159
↓ 3 callersMethodsend_back
(self, parent: str, message_num: int, payload: bytes)
src/cowrie/ssh_proxy/protocols/ssh.py:376
↓ 3 callersMethodsend_message
(self, message)
src/cowrie/output/telegram.py:59
↓ 3 callersMethodset_parent
(self, parent)
src/cowrie/pool_interface/client.py:29
↓ 3 callersMethodshort_help
(self)
src/cowrie/commands/sudo.py:73
↓ 3 callersMethodstop_pool
(self)
src/backend_pool/pool_service.py:158
↓ 3 callersMethodswitch_user
Switch to the target user and start a new shell.
src/cowrie/commands/su.py:130
↓ 3 callersMethodtelnet_WONT
Client refuses to enable an option.
src/cowrie/telnet/transport.py:221
↓ 3 callersMethodtransmission_error
(self, batch)
src/cowrie/output/dshield.py:137
↓ 3 callersFunctionuname_get_some_help
()
src/cowrie/commands/uname.py:63
↓ 3 callersMethodupdate_one
(self, collection, session, doc)
src/cowrie/output/mongodb.py:28
↓ 3 callersMethodupdate_pwd
(self, directory)
src/cowrie/scripts/fsctl.py:393
↓ 3 callersMethodwontChain
(self, option)
src/cowrie/telnet/transport.py:142
↓ 2 callersMethod__init__
(self, user, password, conn)
src/backend_pool/ssh_exec.py:18
↓ 2 callersFunction_authentication
Fill in the OCSF 'Authentication' (class_uid 3002) scaffolding for Cowrie login attempts. This is the Identity & Access Management category,
src/cowrie/core/ocsf.py:123
↓ 2 callersMethod_backtick_source
(self, line: str, node: Tree)
src/cowrie/shell/bashparse.py:940
↓ 2 callersMethod_begin_download
Prepare transfer bookkeeping and display status
src/cowrie/commands/wget.py:396
↓ 2 callersMethod_build_system_context
Build the system context prompt, using the configured template if present. Supports variables: {hostname}, {username}, {ip}, {ip6}, {
src/cowrie/llm/protocol.py:144
↓ 2 callersMethod_capture
(self, run: Callable[[], None])
src/cowrie/test/test_telnet_transport.py:257
↓ 2 callersMethod_capture
(self, run: Callable[[], None])
src/cowrie/test/test_telnet_transport.py:293
↓ 2 callersMethod_closed_event
(self, mock_msg: MagicMock)
src/cowrie/test/test_session_duration.py:28
↓ 2 callersMethod_connect
Establish a connection to RabbitMQ and declare the exchange.
src/cowrie/output/rmq.py:64
↓ 2 callersMethod_consume_empty_parens
(self, cursor: _Cursor)
src/cowrie/shell/bashparse.py:708
↓ 2 callersMethod_create_collection
Create the configured collection and store its server-assigned id.
src/cowrie/output/virustotal.py:604
↓ 2 callersFunction_data_resource
Build a Traversable for cowrie.data/<parts> using chained joinpath.
src/cowrie/core/resources.py:26
↓ 2 callersMethod_event
(self, mock_msg: MagicMock, eventid: str)
src/cowrie/test/test_session_duration.py:22
↓ 2 callersMethod_expand_embedded
Expand a ``$VAR`` reference that is embedded in a larger word. A set variable expands to its value (empty included); an unset referen
src/cowrie/shell/bashparse.py:869
↓ 2 callersFunction_file_transfer
Map a Cowrie file_download / file_upload event onto File System Activity. Both events result in a new file written to the honeypot (fetched
src/cowrie/core/ocsf.py:272
↓ 2 callersFunction_filesystem_activity
Fill in the shared OCSF 'File System Activity' (class_uid 1001) scaffolding. The acting process is always Cowrie itself; the per-event file o
src/cowrie/core/ocsf.py:246
↓ 2 callersMethod_finish
The command queue is drained: do the shell's idle action. An interactive shell shows the next prompt. A top-level non-interactive she
src/cowrie/shell/honeypot.py:237
↓ 2 callersMethod_finish_function
( self, line: str, cursor: _Cursor, name: str, op: str | None )
src/cowrie/shell/bashparse.py:717
↓ 2 callersMethod_group_source
Raw source of the inner ``start`` tree of a ``$(...)`` or ``(...)``.
src/cowrie/shell/bashparse.py:931
↓ 2 callersMethod_is_new_shasum
(self, shasum)
src/cowrie/output/virustotal.py:129
↓ 2 callersMethod_kex_event
(self, packet: bytes)
src/cowrie/test/test_ssh_transport.py:44
↓ 2 callersFunction_kexinit_payload
Build a minimal SSH_MSG_KEXINIT payload with the given kex name-list. Layout (RFC 4253): 16-byte cookie, then 10 name-list strings, then a bo
src/cowrie/test/test_ssh_transport.py:19
↓ 2 callersMethod_loop_body_end
The continuation appended after a loop body. It consumes a pending break / continue (break ends the loop; continue and a normal pass both
src/cowrie/shell/honeypot.py:304
↓ 2 callersMethod_make_output
(self)
src/cowrie/test/test_misp.py:41
↓ 2 callersMethod_maybe_postfile
(self, outfile, fileName)
src/cowrie/output/cuckoo.py:88
↓ 2 callersFunction_open
()
src/cowrie/shell/honeyfs.py:84
↓ 2 callersMethod_parse_brace_group
( self, line: str, cursor: _Cursor, op: str | None )
src/cowrie/shell/bashparse.py:667
↓ 2 callersMethod_parse_scan_results
Parse scan results into standardized format
src/cowrie/output/virustotal.py:206
↓ 2 callersMethod_parser
(self)
src/cowrie/test/test_customparser.py:19
↓ 2 callersFunction_process_activity
Fill in the OCSF 'Process Activity' (class_uid 1007) scaffolding for commands the attacker runs in the shell. This is the System Activity
src/cowrie/core/ocsf.py:199
↓ 2 callersMethod_safe_exit
Safely exit command, handling case where already removed from cmdstack
src/cowrie/commands/tftp.py:403
↓ 2 callersMethod_schedule
(self, delay: float)
src/cowrie/output/discord.py:98
↓ 2 callersMethod_send_http
Issue the webhook POST request and return Deferred with (code, retry_after).
src/cowrie/output/discord.py:102
↓ 2 callersMethod_setAttrs
(self, path, attrs)
src/cowrie/shell/filetransfer.py:192
↓ 2 callersMethod_short_circuit
Whether a statement joined by ``op`` should be skipped given the last command's exit status: ``&&`` after a failure, ``||`` after a success.
src/cowrie/shell/honeypot.py:255
↓ 2 callersMethod_special_param
Expand a special parameter ($?, $@, $#, ...) to its string value, or None for an ordinary ``$name`` reference the caller should look up.
src/cowrie/shell/bashparse.py:886
↓ 2 callersMethod_split_statements
Recursive-descent parse of the flat token stream into statements.
src/cowrie/shell/bashparse.py:387
↓ 2 callersMethod_stat
(self, path: str)
src/cowrie/commands/base.py:1374
↓ 2 callersMethod_subshell_statements
Parse the inner ``start`` tree of a ``(...)`` group into statements.
src/cowrie/shell/bashparse.py:924
↓ 2 callersFunction_tree
Load the filesystem pickle once and cache it for the process lifetime. Resolution: 1. If [shell] filesystem is set, load that file. 2
src/cowrie/shell/honeyfs.py:69
↓ 2 callersMethod_word_source
The raw source text of a word, for keywords and case patterns.
src/cowrie/shell/bashparse.py:759
↓ 2 callersMethod_write_to_fd
(self, fd: int, data: bytes)
src/cowrie/shell/pipe.py:346
↓ 2 callersMethod_write_to_terminal
(self, data: bytes)
src/cowrie/shell/pipe.py:333
↓ 2 callersMethodaddPacket
(self, parent: str, data: bytes)
src/cowrie/telnet_proxy/handler.py:181
↓ 2 callersMethodadd_sighting
Add a sighting to an existing attribute
src/cowrie/output/misp.py:282
↓ 2 callersMethodarg_missing
Print missing argument message, and exit
src/cowrie/commands/gcc.py:232
↓ 2 callersMethodauthenticateBackend
This is called when the frontend is authenticated, so as to give us the option to authenticate with the username and password given b
src/cowrie/ssh_proxy/client_transport.py:70
← previousnext →201–300 of 2,302, ranked by callers