What have you seen them do?
* Download a large file (e.g. XP SP3) from Microsofts servers to test bandwidth * Download IP scanners and trying to run them (in order to find new hosts to attack) * Download botnet code that connects to some C2 server
Tools they download were often downloaded as source, which they then tried to compile in order to run it.
Searching for e.g. 'youtube kippo' will get you videos of honeypot sessions.