MCP serverai.tunnelmind/scry
Free IPv4 lookups against a distributed attacker-observation corpus.
Overview
Score?
UNRATED 0.575
of what a free look can see, on 27 looks
Looks
30
last 5 hr ago
Tools
12
More info
URL
mcp.tunnelmind.ai/mcp
streamable-http
Says it is
scry 0.5.0
protocol 2025-03-26
In the record since
32 days ago
Among servers18,413 with a card
0median 0.606 · this server 0.575 · highest on record 0.8561
Toolsfrom sha256:cf91853ef4…a4d5be
| Tool | Schema |
|---|---|
| scry_asn Roll-up of corpus activity for a single ASN — observation count, distinct source IPs, actor count, scanner count, high-confidence actor count, and per-protocol breakdown. |
input · no output |
| scry_campaign Single campaign detail by id (format: c[0-9a-f]{15}). |
input · no output |
| scry_campaigns Active threat campaigns — coordinated attacker activity that exceeds the noise floor. ≥5 distinct actors, ≥3 ASNs, ≤5 destination ports, ≥1h history. |
input · no output |
| scry_check Returns Scry's corpus knowledge for a single IPv4 address: when it was first/last
observed, observation count, protocols and ports targeted, ASN, country, category
(actor/scanner/n |
input · no output |
| scry_check_bulk Look up many IPv4 addresses in one request. Up to 100 IPs per call. Same per-IP shape as scry_check, keyed by IP. |
input · no output |
| scry_country Roll-up of corpus activity by ISO country code. Same shape as scry_asn. |
input · no output |
| scry_recent Recent observations feed — aggregated by source IP within a time window. Cursor-paginated via since_ms. |
input · no output |
| scry_stats Returns aggregate Scry corpus telemetry: total observation count, distinct
source IPs, first/last observation timestamps, last-24h activity, and
per-protocol breakdowns. Useful as |
input · no output |
| scry_timeseries Bucketed observation counts over time. Detect bursts, plot trends, sanity-check whether attacker activity is rising or falling. |
input · no output |
| scry_tool Single tool detail by 16-char hex id from scry_tools. |
input · no output |
| scry_tools List detected attack tools — (protocol, payload, path) tuples sent by 3+ distinct source IPs. Aggregate metadata only; never lists member actors. |
input · no output |
| scry_top Top-N source dimensions over a time window. Useful for situational awareness — 'where is the noise coming from right now?' |
input · no output |
Verify it yourself
npx teppi-check https://mcp.tunnelmind.ai/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1FZ2394XQ12WGMBJWMG7QA7