Heralding

Input—per 1M tokens
Output—per 1M tokens
Context—tokens
WeightsClosed

About

Heralding is ranked #8 of 18 in honeypot software on Inferse. It runs on Linux, Self-hosted. There is a free plan.

Compared on honeypot software

Free plan
Yesgithub.com
Deployment model
self-hostedgithub.com
Decoy scope
networkgithub.com
Credential lures
Yesgithub.com

Facts

Purpose
Heralding is a simple honeypot that collects credentials.github.com · 3 Oct 2026
Protocols
It supports FTP, Telnet, SSH, HTTP, HTTPS, POP3, POP3S, IMAP, IMAPS, SMTP, VNC, PostgreSQL and SOCKS5.github.com · 3 Oct 2026
Authentication capture
The auth log records usernames and plaintext passwords when the protocol makes them available.github.com · 3 Oct 2026
Session logs
It writes authentication attempts, session summaries and complete session data to CSV and JSON Lines files.github.com · 3 Oct 2026
Session details
Session data can include timestamps, duration, source and destination IP and port, protocol, authentication attempts and protocol-specific auxiliary data.github.com · 3 Oct 2026
Log timing
Session log entries are written after a session ends, while auth log entries appear when a password has been transmitted.github.com · 3 Oct 2026
Installation
The README gives pip installation instructions and describes running Heralding on a Debian-based system.github.com · 3 Oct 2026
Container deployment
The project README describes building a Docker image and running it with a port mapping.github.com · 3 Oct 2026
Requirements
The README states that Python 3.7.0 or higher is required.github.com · 3 Oct 2026
Packet capture
The README points to Curisoum for creating a separate PCAP for each Heralding session and says to enable it in Heralding.yml.github.com · 3 Oct 2026
License
GitHub identifies the project as GPL-3.0 licensed.github.com · 3 Oct 2026
Intended users
The project describes itself as a honeypot for users who want to collect credentials.github.com · 3 Oct 2026

Best Heralding alternatives

See all 12

Where it ranks on Inferse

Sources