
Heralding
Summary
Heralding is a free, self-hosted network honeypot for collecting credentials. It runs on Linux and supports FTP, Telnet, SSH, HTTP, HTTPS, POP3, POP3S, IMAP, IMAPS, SMTP, VNC, PostgreSQL, and SOCKS5. Its authentication log records usernames and plaintext passwords when the protocol makes them available. Heralding also writes authentication attempts, session summaries, and complete session data to CSV and JSON Lines files. Session information can include timestamps, duration, source and destination IP addresses and ports, protocol, authentication attempts, and protocol-specific auxiliary data. Session log entries are written after sessions end, while authentication entries appear when a password has been transmitted. The README describes pip installation on Debian-based systems and Docker deployment with port mapping. It requires Python 3.7.0 or higher. The README also points to Curisoum for separate packet captures per session and says to enable it in Heralding.yml. GitHub identifies the project as GPL-3.0 licensed.
Who it is for
Heralding suits users who want to collect credentials with a self-hosted Linux honeypot. It may also suit users who need authentication and session details saved to CSV or JSON Lines files.
What is good
- Supports a broad list of network protocols
- Writes session data to CSV and JSON Lines
- Offers pip and Docker deployment guidance
- Free and GPL-3.0 licensed
What to know first
- Requires Python 3.7.0 or higher
- Session logs are written after a session ends
- Plaintext password capture depends on protocol availability
Verdict
Heralding records credential attempts and session details across many protocols, with pip and Docker deployment guidance. Account for its Python requirement and the fact that session logs arrive after sessions end.
Heralding plans and pricing
All plansCompared on honeypot software
- Free plan
- Yesgithub.com
- Deployment model
- self-hostedgithub.com
- Decoy scope
- networkgithub.com
- Credential lures
- Yesgithub.com
Facts
- Purpose
- Heralding is a simple honeypot that collects credentials.github.com · 3 Oct 2026
- Protocols
- It supports FTP, Telnet, SSH, HTTP, HTTPS, POP3, POP3S, IMAP, IMAPS, SMTP, VNC, PostgreSQL and SOCKS5.github.com · 3 Oct 2026
- Authentication capture
- The auth log records usernames and plaintext passwords when the protocol makes them available.github.com · 3 Oct 2026
- Session logs
- It writes authentication attempts, session summaries and complete session data to CSV and JSON Lines files.github.com · 3 Oct 2026
- Session details
- Session data can include timestamps, duration, source and destination IP and port, protocol, authentication attempts and protocol-specific auxiliary data.github.com · 3 Oct 2026
- Log timing
- Session log entries are written after a session ends, while auth log entries appear when a password has been transmitted.github.com · 3 Oct 2026
- Installation
- The README gives pip installation instructions and describes running Heralding on a Debian-based system.github.com · 3 Oct 2026
- Container deployment
- The project README describes building a Docker image and running it with a port mapping.github.com · 3 Oct 2026
- Requirements
- The README states that Python 3.7.0 or higher is required.github.com · 3 Oct 2026
- Packet capture
- The README points to Curisoum for creating a separate PCAP for each Heralding session and says to enable it in Heralding.yml.github.com · 3 Oct 2026
- License
- GitHub identifies the project as GPL-3.0 licensed.github.com · 3 Oct 2026
- Intended users
- The project describes itself as a honeypot for users who want to collect credentials.github.com · 3 Oct 2026
Best Heralding alternatives
See all 12Where it ranks on Everything Xiaomi
- Best Honeypot Software in 2026#5 of 18
Is Heralding yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- github.com/johnnykv/heralding· checked 3 Oct 2026




