MCP servernet.honeylabs/mcp
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
Overview
Score?
UNRATED 0.810
of what a free look can see, on 31 looks
Looks
35
last 9 hr ago
Tools
10
changed 3 days ago
More info
URL
mcp.honeylabs.net/mcp
streamable-http
Says it is
HoneyLabs Threat Intelligence 1.0.0
protocol 2025-06-18
In the record since
32 days ago
Among servers18,413 with a card
0median 0.606 · this server 0.810 · highest on record 0.8561
Toolsfrom sha256:f3f3d433de…86e680 · +0 −0 3 days ago
| Tool | Schema |
|---|---|
| asn_enrich_tool Full honeypot profile for an ASN (autonomous system / hosting provider). Use for:
'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks from this
hosting provi |
input · no output |
| attack_timeline_tool Attack volume over time, bucketed by hour or day. Use for: 'show attack trends this
week', 'was there a spike on port 22?', 'how has SSH scanning changed?', 'attack volume
from Chi |
input · no output |
| cve_lookup_tool Who is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577
being exploited in the wild?', 'who is scanning for this CVE?', 'show me actors probing
CVE-2023 |
input · no output |
| fingerprint_population_tool The population behind a single client fingerprint: how many source IPs carry it,
across how many networks (ASNs) and countries, the ports they hit, the top networks
and a sample of |
input · no output |
| fingerprint_search_tool Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks:
'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?', 'how
common is this |
input · no output |
| fingerprint_similar_tool Request shapes within a few headers of an Akin HTTP fingerprint, with what
those clients ask for and call themselves, plus the family the token belongs
to. Use when one odd request |
input · no output |
| ioc_lookup_tool Look up any IP address, CIDR network, set of networks, or domain in the honeypot
dataset. Use this FIRST whenever the
user asks: 'is this IP malicious?', 'is this a known s |
input · no output |
| payload_search_tool Literal substring search over captured request text: URL path, request body,
request headers and event summary. Use for: 'find attacks targeting /wp-admin',
'find requests with thi |
input · no output |
| search_events_tool Return individual raw honeypot events with all fields. Use when the user wants to see
actual records: 'show me events from this IP', 'what hit port 443 last week', 'events from
Rus |
input · no output |
| top_attackers_tool Ranked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top
attacking countries', 'most targeted ports', 'most common user agents', 'top ASNs by
attack volume |
input · no output |
Verify it yourself
npx teppi-check https://mcp.honeylabs.net/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1FZ2Q3CP5HG3XMQSCYNX557