The Heralding homepage
Score6.7
Rank#5 of 18
PriceFree
Free planYes
Runs onLinux, Self-hosted

Summary

Heralding is a free, self-hosted network honeypot for collecting credentials. It runs on Linux and supports FTP, Telnet, SSH, HTTP, HTTPS, POP3, POP3S, IMAP, IMAPS, SMTP, VNC, PostgreSQL, and SOCKS5. Its authentication log records usernames and plaintext passwords when the protocol makes them available. Heralding also writes authentication attempts, session summaries, and complete session data to CSV and JSON Lines files. Session information can include timestamps, duration, source and destination IP addresses and ports, protocol, authentication attempts, and protocol-specific auxiliary data. Session log entries are written after sessions end, while authentication entries appear when a password has been transmitted. The README describes pip installation on Debian-based systems and Docker deployment with port mapping. It requires Python 3.7.0 or higher. The README also points to Curisoum for separate packet captures per session and says to enable it in Heralding.yml. GitHub identifies the project as GPL-3.0 licensed.

Who it is for

Heralding suits users who want to collect credentials with a self-hosted Linux honeypot. It may also suit users who need authentication and session details saved to CSV or JSON Lines files.

What is good

  • Supports a broad list of network protocols
  • Writes session data to CSV and JSON Lines
  • Offers pip and Docker deployment guidance
  • Free and GPL-3.0 licensed

What to know first

  • Requires Python 3.7.0 or higher
  • Session logs are written after a session ends
  • Plaintext password capture depends on protocol availability

Verdict

Heralding records credential attempts and session details across many protocols, with pip and Docker deployment guidance. Account for its Python requirement and the fact that session logs arrive after sessions end.

Heralding plans and pricing

All plans
Heralding Free GPL-3.0 licensed open-source honeypot github.com · 3 Oct 2026

Compared on honeypot software

Free plan
Yesgithub.com
Deployment model
self-hostedgithub.com
Decoy scope
networkgithub.com
Credential lures
Yesgithub.com

Facts

Purpose
Heralding is a simple honeypot that collects credentials.github.com · 3 Oct 2026
Protocols
It supports FTP, Telnet, SSH, HTTP, HTTPS, POP3, POP3S, IMAP, IMAPS, SMTP, VNC, PostgreSQL and SOCKS5.github.com · 3 Oct 2026
Authentication capture
The auth log records usernames and plaintext passwords when the protocol makes them available.github.com · 3 Oct 2026
Session logs
It writes authentication attempts, session summaries and complete session data to CSV and JSON Lines files.github.com · 3 Oct 2026
Session details
Session data can include timestamps, duration, source and destination IP and port, protocol, authentication attempts and protocol-specific auxiliary data.github.com · 3 Oct 2026
Log timing
Session log entries are written after a session ends, while auth log entries appear when a password has been transmitted.github.com · 3 Oct 2026
Installation
The README gives pip installation instructions and describes running Heralding on a Debian-based system.github.com · 3 Oct 2026
Container deployment
The project README describes building a Docker image and running it with a port mapping.github.com · 3 Oct 2026
Requirements
The README states that Python 3.7.0 or higher is required.github.com · 3 Oct 2026
Packet capture
The README points to Curisoum for creating a separate PCAP for each Heralding session and says to enable it in Heralding.yml.github.com · 3 Oct 2026
License
GitHub identifies the project as GPL-3.0 licensed.github.com · 3 Oct 2026
Intended users
The project describes itself as a honeypot for users who want to collect credentials.github.com · 3 Oct 2026

Best Heralding alternatives

See all 12

Where it ranks on Everything Xiaomi

Is Heralding yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources