DEF CON 33 - SSH Honeypots and Walkthrough Workshops: A History - Ryan Mitchell

DEF CON 33 - SSH Honeypots and Walkthrough Workshops: A History - Ryan Mitchell

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 34:41

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Ryan Mitchell shares his journey with SSH honeypots, particularly Cowrie, at Defcon's packet hacking village, emphasizing how these security tools can be transformed into engaging, playful challenges that preserve the creative spirit of hacker culture 0:22-9:57.

Key Takeaways:
• Mitchell discovered SSH honeypots in 2016 when he encountered an unusual SSH entry on the wall of sheep, leading to his fascination with these deceptive security tools 3:42-6:30.
• Cowrie honeypots are medium-interaction systems that support Telnet and SSH protocols, allowing for realistic interactions while remaining securely contained 7:36-9:57.
• The packet hacking village's walkthrough workshops, which began in 2018, teach participants of all skill levels how to set up and configure SSH honeypots through step-by-step guidance 9:57-14:24.
• Mitchell has created numerous creative honeypot challenges since 2017, incorporating storytelling, puzzles, and themes ranging from Seattle geography to Gibson hacking and existential AI 17:14-28:19.
• His 2025 challenge features an AI-themed narrative where players interact with an AI character named M, showcasing the continued evolution of honeypots as educational and entertaining tools 27:07-32:03.

Mitchell's work demonstrates how security tools can be transformed into engaging experiences that foster learning and preserve the playful elements of hacker culture 33:31-34:08.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

And it's now the top of the hour. It is 4 o'clock p.m. in Las Vegas at Defcon 33. Welcome. Uh and it's my honor to introduce to you uh the speaker uh and a partner in crime, Ryan Mitchell to talk about SSH 20 pots. All right. Hi. So, I'm Ryan Mitchell. Um, and I'm here to talk about my two favorite things besides I guess my family, which is SSH honeypotss and walkthrough workshops at the packet hacking village. Um, so I realized that the word honeypot could refer to a great many things here at Defcon, but for the purposes of this talk, uh, unless specified otherwise, a honeypot refers to an SSH honeypot. So, a little bit about me. Uh, I'm not a networking or an IT person. I'm a software engineer and I've done this nothing else, nothing but software engineering basically my whole career. um…