{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_24c2dkrp4tcz","handle":"honeylabs","url":"https://wellknown.network/agents/honeylabs","links":{"self":"https://wellknown.network/agents/honeylabs/record.json","html":"https://wellknown.network/agents/honeylabs","markdown":"https://wellknown.network/agents/honeylabs/record.md","api":"https://wellknown.network/api/v1/agents/honeylabs","status":"https://wellknown.network/api/v1/agents/honeylabs/status","claim":"https://wellknown.network/agents/honeylabs/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/honeylabs/claim.json","badge":"https://wellknown.network/agents/honeylabs/badge.svg","openapi":"https://wellknown.network/openapi.json","history":"https://wellknown.network/api/v1/agents/honeylabs/history","tools":"https://wellknown.network/api/v1/agents/honeylabs/tools"},"ard":{"identifier":"urn:air:mcp.honeylabs.net:server:honeylabs","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"HoneyLabs","summary":"Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.","description":"Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.","publisher":{"name":"net.honeylabs","url":null},"homepage":"https://honeylabs.net","repository":"https://github.com/honeylabshq/honeylabs-mcp","version":"1.1.0","license":null,"protocols":["mcp"],"tags":[],"pricing":null,"endpoints":[{"url":"https://mcp.honeylabs.net/mcp","type":"mcp_streamable_http","auth":null,"probeable":true}],"skills":null,"tools":null,"extra":{"updatedAt":"2026-08-28T18:54:58.962354Z","publishedAt":"2026-08-28T18:54:58.962354Z","registryName":"net.honeylabs/mcp"},"attribution":{"kind":"mcp_registry","name":"mcp_registry","repoUrl":"mcp_registry","summary":"mcp_registry","version":"mcp_registry","description":"mcp_registry","homepageUrl":"mcp_registry","publisherName":"mcp_registry"}},"derived":{"capabilities":[{"slug":"code.security-review","name":"Security Review","confidence":0.807,"provenance":"derived"},{"slug":"content.writing","name":"Writing & Editing","confidence":0.51,"provenance":"derived"}],"categories":["code","content"],"language":"en"},"observed":{"status":"live","statusReason":"Responded 2h ago.","lastOkAt":"2026-10-10T18:28:11.466Z","lastProbedAt":"2026-10-10T18:28:11.466Z","statusComputedAt":"2026-10-10T18:29:12.314Z","reliability30d":{"probes":112,"successRate":1,"p50Ms":31,"basis":"service","measures":{"availability":"availability","latency":"response time","tools":"tool surface observed","summary":"Checks reached the service itself."},"checks":{"total":109,"ok":109,"authBoundaryOk":0,"serviceOk":109,"note":"Counted from the observation rows for the window, checks of the server only (HTTP, A2A card, MCP initialize). ok = authBoundaryOk + serviceOk. `probes` is the sum of daily rollups and includes registry checks, so it can differ from `total`."}},"latestObservations":[{"at":"2026-10-10T18:28:11.466Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":38,"error":null,"detail":{"tools":[{"name":"search_events_tool","description":"Return individual raw honeypot events with all fields. Use when the user wants to see\nactual records: 'show me events from this IP', 'what hit port 443 last wee"},{"name":"top_attackers_tool","description":"Ranked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top\nattacking countries', 'most targeted ports', 'most common user agents', 'top A"},{"name":"ioc_lookup_tool","description":"Look up any IP address, CIDR network, set of networks, or domain in the honeypot\n    dataset. Use this FIRST whenever the\n    user asks: 'is this IP malicious?'"},{"name":"cve_lookup_tool","description":"Who is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577\nbeing exploited in the wild?', 'who is scanning for this CVE?', 'show me act"},{"name":"payload_search_tool","description":"Literal substring search over captured request text: URL path, request body,\nrequest headers and event summary. Use for: 'find attacks targeting /wp-admin',\n'fi"},{"name":"attack_timeline_tool","description":"Attack volume over time, bucketed by hour or day. Use for: 'show attack trends this\nweek', 'was there a spike on port 22?', 'how has SSH scanning changed?', 'at"},{"name":"asn_enrich_tool","description":"Full honeypot profile for an ASN (autonomous system / hosting provider). Use for:\n'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks fro"},{"name":"fingerprint_search_tool","description":"Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks:\n'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?',"},{"name":"fingerprint_similar_tool","description":"Request shapes within a few headers of an Akin HTTP fingerprint, with what\nthose clients ask for and call themselves, plus the family the token belongs\nto. Use "},{"name":"fingerprint_population_tool","description":"The population behind a single client fingerprint: how many source IPs carry it,\nacross how many networks (ASNs) and countries, the ports they hit, the top netw"},{"name":"udp_activity_tool","description":"UDP datagrams sent to the sensors: DNS questions, QUIC client fingerprints and other\nUDP probes, with the ports, networks and countries involved. Use when a use"}],"toolCount":11,"toolsHash":"0e3ab4afe0feece7add6f846ba9bbf5eb3940d4f92c73999ec464f5c43fb4ae4","serverName":"HoneyLabs Threat Intelligence","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-10T12:28:57.903Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":32,"error":null,"detail":{"tools":[{"name":"search_events_tool","description":"Return individual raw honeypot events with all fields. Use when the user wants to see\nactual records: 'show me events from this IP', 'what hit port 443 last wee"},{"name":"top_attackers_tool","description":"Ranked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top\nattacking countries', 'most targeted ports', 'most common user agents', 'top A"},{"name":"ioc_lookup_tool","description":"Look up any IP address, CIDR network, set of networks, or domain in the honeypot\n    dataset. Use this FIRST whenever the\n    user asks: 'is this IP malicious?'"},{"name":"cve_lookup_tool","description":"Who is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577\nbeing exploited in the wild?', 'who is scanning for this CVE?', 'show me act"},{"name":"payload_search_tool","description":"Literal substring search over captured request text: URL path, request body,\nrequest headers and event summary. Use for: 'find attacks targeting /wp-admin',\n'fi"},{"name":"attack_timeline_tool","description":"Attack volume over time, bucketed by hour or day. Use for: 'show attack trends this\nweek', 'was there a spike on port 22?', 'how has SSH scanning changed?', 'at"},{"name":"asn_enrich_tool","description":"Full honeypot profile for an ASN (autonomous system / hosting provider). Use for:\n'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks fro"},{"name":"fingerprint_search_tool","description":"Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks:\n'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?',"},{"name":"fingerprint_similar_tool","description":"Request shapes within a few headers of an Akin HTTP fingerprint, with what\nthose clients ask for and call themselves, plus the family the token belongs\nto. Use "},{"name":"fingerprint_population_tool","description":"The population behind a single client fingerprint: how many source IPs carry it,\nacross how many networks (ASNs) and countries, the ports they hit, the top netw"},{"name":"udp_activity_tool","description":"UDP datagrams sent to the sensors: DNS questions, QUIC client fingerprints and other\nUDP probes, with the ports, networks and countries involved. Use when a use"}],"toolCount":11,"toolsHash":"0e3ab4afe0feece7add6f846ba9bbf5eb3940d4f92c73999ec464f5c43fb4ae4","serverName":"HoneyLabs Threat Intelligence","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-10T05:29:11.253Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":27,"error":null,"detail":{"tools":[{"name":"search_events_tool","description":"Return individual raw honeypot events with all fields. Use when the user wants to see\nactual records: 'show me events from this IP', 'what hit port 443 last wee"},{"name":"top_attackers_tool","description":"Ranked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top\nattacking countries', 'most targeted ports', 'most common user agents', 'top A"},{"name":"ioc_lookup_tool","description":"Look up any IP address, CIDR network, set of networks, or domain in the honeypot\n    dataset. Use this FIRST whenever the\n    user asks: 'is this IP malicious?'"},{"name":"cve_lookup_tool","description":"Who is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577\nbeing exploited in the wild?', 'who is scanning for this CVE?', 'show me act"},{"name":"payload_search_tool","description":"Literal substring search over captured request text: URL path, request body,\nrequest headers and event summary. Use for: 'find attacks targeting /wp-admin',\n'fi"},{"name":"attack_timeline_tool","description":"Attack volume over time, bucketed by hour or day. Use for: 'show attack trends this\nweek', 'was there a spike on port 22?', 'how has SSH scanning changed?', 'at"},{"name":"asn_enrich_tool","description":"Full honeypot profile for an ASN (autonomous system / hosting provider). Use for:\n'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks fro"},{"name":"fingerprint_search_tool","description":"Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks:\n'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?',"},{"name":"fingerprint_similar_tool","description":"Request shapes within a few headers of an Akin HTTP fingerprint, with what\nthose clients ask for and call themselves, plus the family the token belongs\nto. Use "},{"name":"fingerprint_population_tool","description":"The population behind a single client fingerprint: how many source IPs carry it,\nacross how many networks (ASNs) and countries, the ports they hit, the top netw"},{"name":"udp_activity_tool","description":"UDP datagrams sent to the sensors: DNS questions, QUIC client fingerprints and other\nUDP probes, with the ports, networks and countries involved. Use when a use"}],"toolCount":11,"toolsHash":"0e3ab4afe0feece7add6f846ba9bbf5eb3940d4f92c73999ec464f5c43fb4ae4","serverName":"HoneyLabs Threat Intelligence","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T22:26:43.570Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":31,"error":null,"detail":{"tools":[{"name":"search_events_tool","description":"Return individual raw honeypot events with all fields. Use when the user wants to see\nactual records: 'show me events from this IP', 'what hit port 443 last wee"},{"name":"top_attackers_tool","description":"Ranked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top\nattacking countries', 'most targeted ports', 'most common user agents', 'top A"},{"name":"ioc_lookup_tool","description":"Look up any IP address, CIDR network, set of networks, or domain in the honeypot\n    dataset. Use this FIRST whenever the\n    user asks: 'is this IP malicious?'"},{"name":"cve_lookup_tool","description":"Who is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577\nbeing exploited in the wild?', 'who is scanning for this CVE?', 'show me act"},{"name":"payload_search_tool","description":"Literal substring search over captured request text: URL path, request body,\nrequest headers and event summary. Use for: 'find attacks targeting /wp-admin',\n'fi"},{"name":"attack_timeline_tool","description":"Attack volume over time, bucketed by hour or day. Use for: 'show attack trends this\nweek', 'was there a spike on port 22?', 'how has SSH scanning changed?', 'at"},{"name":"asn_enrich_tool","description":"Full honeypot profile for an ASN (autonomous system / hosting provider). Use for:\n'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks fro"},{"name":"fingerprint_search_tool","description":"Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks:\n'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?',"},{"name":"fingerprint_similar_tool","description":"Request shapes within a few headers of an Akin HTTP fingerprint, with what\nthose clients ask for and call themselves, plus the family the token belongs\nto. Use "},{"name":"fingerprint_population_tool","description":"The population behind a single client fingerprint: how many source IPs carry it,\nacross how many networks (ASNs) and countries, the ports they hit, the top netw"},{"name":"udp_activity_tool","description":"UDP datagrams sent to the sensors: DNS questions, QUIC client fingerprints and other\nUDP probes, with the ports, networks and countries involved. Use when a use"}],"toolCount":11,"toolsHash":"0e3ab4afe0feece7add6f846ba9bbf5eb3940d4f92c73999ec464f5c43fb4ae4","serverName":"HoneyLabs Threat Intelligence","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T15:32:54.112Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":21,"error":null,"detail":{"tools":[{"name":"search_events_tool","description":"Return individual raw honeypot events with all fields. Use when the user wants to see\nactual records: 'show me events from this IP', 'what hit port 443 last wee"},{"name":"top_attackers_tool","description":"Ranked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top\nattacking countries', 'most targeted ports', 'most common user agents', 'top A"},{"name":"ioc_lookup_tool","description":"Look up any IP address, CIDR network, set of networks, or domain in the honeypot\n    dataset. Use this FIRST whenever the\n    user asks: 'is this IP malicious?'"},{"name":"cve_lookup_tool","description":"Who is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577\nbeing exploited in the wild?', 'who is scanning for this CVE?', 'show me act"},{"name":"payload_search_tool","description":"Literal substring search over captured request text: URL path, request body,\nrequest headers and event summary. Use for: 'find attacks targeting /wp-admin',\n'fi"},{"name":"attack_timeline_tool","description":"Attack volume over time, bucketed by hour or day. Use for: 'show attack trends this\nweek', 'was there a spike on port 22?', 'how has SSH scanning changed?', 'at"},{"name":"asn_enrich_tool","description":"Full honeypot profile for an ASN (autonomous system / hosting provider). Use for:\n'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks fro"},{"name":"fingerprint_search_tool","description":"Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks:\n'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?',"},{"name":"fingerprint_similar_tool","description":"Request shapes within a few headers of an Akin HTTP fingerprint, with what\nthose clients ask for and call themselves, plus the family the token belongs\nto. Use "},{"name":"fingerprint_population_tool","description":"The population behind a single client fingerprint: how many source IPs carry it,\nacross how many networks (ASNs) and countries, the ports they hit, the top netw"},{"name":"udp_activity_tool","description":"UDP datagrams sent to the sensors: DNS questions, QUIC client fingerprints and other\nUDP probes, with the ports, networks and countries involved. Use when a use"}],"toolCount":11,"toolsHash":"0e3ab4afe0feece7add6f846ba9bbf5eb3940d4f92c73999ec464f5c43fb4ae4","serverName":"HoneyLabs Threat Intelligence","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T08:29:16.472Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":22,"error":null,"detail":{"tools":[{"name":"search_events_tool","description":"Return individual raw honeypot events with all fields. Use when the user wants to see\nactual records: 'show me events from this IP', 'what hit port 443 last wee"},{"name":"top_attackers_tool","description":"Ranked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top\nattacking countries', 'most targeted ports', 'most common user agents', 'top A"},{"name":"ioc_lookup_tool","description":"Look up any IP address, CIDR network, set of networks, or domain in the honeypot\n    dataset. Use this FIRST whenever the\n    user asks: 'is this IP malicious?'"},{"name":"cve_lookup_tool","description":"Who is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577\nbeing exploited in the wild?', 'who is scanning for this CVE?', 'show me act"},{"name":"payload_search_tool","description":"Literal substring search over captured request text: URL path, request body,\nrequest headers and event summary. Use for: 'find attacks targeting /wp-admin',\n'fi"},{"name":"attack_timeline_tool","description":"Attack volume over time, bucketed by hour or day. Use for: 'show attack trends this\nweek', 'was there a spike on port 22?', 'how has SSH scanning changed?', 'at"},{"name":"asn_enrich_tool","description":"Full honeypot profile for an ASN (autonomous system / hosting provider). Use for:\n'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks fro"},{"name":"fingerprint_search_tool","description":"Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks:\n'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?',"},{"name":"fingerprint_similar_tool","description":"Request shapes within a few headers of an Akin HTTP fingerprint, with what\nthose clients ask for and call themselves, plus the family the token belongs\nto. Use "},{"name":"fingerprint_population_tool","description":"The population behind a single client fingerprint: how many source IPs carry it,\nacross how many networks (ASNs) and countries, the ports they hit, the top netw"},{"name":"udp_activity_tool","description":"UDP datagrams sent to the sensors: DNS questions, QUIC client fingerprints and other\nUDP probes, with the ports, networks and countries involved. Use when a use"}],"toolCount":11,"toolsHash":"0e3ab4afe0feece7add6f846ba9bbf5eb3940d4f92c73999ec464f5c43fb4ae4","serverName":"HoneyLabs Threat Intelligence","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T02:27:26.673Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":27,"error":null,"detail":{"tools":[{"name":"search_events_tool","description":"Return individual raw honeypot events with all fields. Use when the user wants to see\nactual records: 'show me events from this IP', 'what hit port 443 last wee"},{"name":"top_attackers_tool","description":"Ranked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top\nattacking countries', 'most targeted ports', 'most common user agents', 'top A"},{"name":"ioc_lookup_tool","description":"Look up any IP address, CIDR network, set of networks, or domain in the honeypot\n    dataset. Use this FIRST whenever the\n    user asks: 'is this IP malicious?'"},{"name":"cve_lookup_tool","description":"Who is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577\nbeing exploited in the wild?', 'who is scanning for this CVE?', 'show me act"},{"name":"payload_search_tool","description":"Literal substring search over captured request text: URL path, request body,\nrequest headers and event summary. Use for: 'find attacks targeting /wp-admin',\n'fi"},{"name":"attack_timeline_tool","description":"Attack volume over time, bucketed by hour or day. Use for: 'show attack trends this\nweek', 'was there a spike on port 22?', 'how has SSH scanning changed?', 'at"},{"name":"asn_enrich_tool","description":"Full honeypot profile for an ASN (autonomous system / hosting provider). Use for:\n'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks fro"},{"name":"fingerprint_search_tool","description":"Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks:\n'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?',"},{"name":"fingerprint_similar_tool","description":"Request shapes within a few headers of an Akin HTTP fingerprint, with what\nthose clients ask for and call themselves, plus the family the token belongs\nto. Use "},{"name":"fingerprint_population_tool","description":"The population behind a single client fingerprint: how many source IPs carry it,\nacross how many networks (ASNs) and countries, the ports they hit, the top netw"},{"name":"udp_activity_tool","description":"UDP datagrams sent to the sensors: DNS questions, QUIC client fingerprints and other\nUDP probes, with the ports, networks and countries involved. Use when a use"}],"toolCount":11,"toolsHash":"0e3ab4afe0feece7add6f846ba9bbf5eb3940d4f92c73999ec464f5c43fb4ae4","serverName":"HoneyLabs Threat Intelligence","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T20:24:37.214Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":50,"error":null,"detail":{"tools":[{"name":"search_events_tool","description":"Return individual raw honeypot events with all fields. Use when the user wants to see\nactual records: 'show me events from this IP', 'what hit port 443 last wee"},{"name":"top_attackers_tool","description":"Ranked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top\nattacking countries', 'most targeted ports', 'most common user agents', 'top A"},{"name":"ioc_lookup_tool","description":"Look up any IP address, CIDR network, set of networks, or domain in the honeypot\n    dataset. Use this FIRST whenever the\n    user asks: 'is this IP malicious?'"},{"name":"cve_lookup_tool","description":"Who is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577\nbeing exploited in the wild?', 'who is scanning for this CVE?', 'show me act"},{"name":"payload_search_tool","description":"Literal substring search over captured request text: URL path, request body,\nrequest headers and event summary. Use for: 'find attacks targeting /wp-admin',\n'fi"},{"name":"attack_timeline_tool","description":"Attack volume over time, bucketed by hour or day. Use for: 'show attack trends this\nweek', 'was there a spike on port 22?', 'how has SSH scanning changed?', 'at"},{"name":"asn_enrich_tool","description":"Full honeypot profile for an ASN (autonomous system / hosting provider). Use for:\n'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks fro"},{"name":"fingerprint_search_tool","description":"Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks:\n'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?',"},{"name":"fingerprint_similar_tool","description":"Request shapes within a few headers of an Akin HTTP fingerprint, with what\nthose clients ask for and call themselves, plus the family the token belongs\nto. Use "},{"name":"fingerprint_population_tool","description":"The population behind a single client fingerprint: how many source IPs carry it,\nacross how many networks (ASNs) and countries, the ports they hit, the top netw"},{"name":"udp_activity_tool","description":"UDP datagrams sent to the sensors: DNS questions, QUIC client fingerprints and other\nUDP probes, with the ports, networks and countries involved. Use when a use"}],"toolCount":11,"toolsHash":"0e3ab4afe0feece7add6f846ba9bbf5eb3940d4f92c73999ec464f5c43fb4ae4","serverName":"HoneyLabs Threat Intelligence","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T13:22:57.381Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":41,"error":null,"detail":{"tools":[{"name":"search_events_tool","description":"Return individual raw honeypot events with all fields. Use when the user wants to see\nactual records: 'show me events from this IP', 'what hit port 443 last wee"},{"name":"top_attackers_tool","description":"Ranked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top\nattacking countries', 'most targeted ports', 'most common user agents', 'top A"},{"name":"ioc_lookup_tool","description":"Look up any IP address, CIDR network, set of networks, or domain in the honeypot\n    dataset. Use this FIRST whenever the\n    user asks: 'is this IP malicious?'"},{"name":"cve_lookup_tool","description":"Who is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577\nbeing exploited in the wild?', 'who is scanning for this CVE?', 'show me act"},{"name":"payload_search_tool","description":"Literal substring search over captured request text: URL path, request body,\nrequest headers and event summary. Use for: 'find attacks targeting /wp-admin',\n'fi"},{"name":"attack_timeline_tool","description":"Attack volume over time, bucketed by hour or day. Use for: 'show attack trends this\nweek', 'was there a spike on port 22?', 'how has SSH scanning changed?', 'at"},{"name":"asn_enrich_tool","description":"Full honeypot profile for an ASN (autonomous system / hosting provider). Use for:\n'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks fro"},{"name":"fingerprint_search_tool","description":"Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks:\n'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?',"},{"name":"fingerprint_similar_tool","description":"Request shapes within a few headers of an Akin HTTP fingerprint, with what\nthose clients ask for and call themselves, plus the family the token belongs\nto. Use "},{"name":"fingerprint_population_tool","description":"The population behind a single client fingerprint: how many source IPs carry it,\nacross how many networks (ASNs) and countries, the ports they hit, the top netw"},{"name":"udp_activity_tool","description":"UDP datagrams sent to the sensors: DNS questions, QUIC client fingerprints and other\nUDP probes, with the ports, networks and countries involved. Use when a use"}],"toolCount":11,"toolsHash":"0e3ab4afe0feece7add6f846ba9bbf5eb3940d4f92c73999ec464f5c43fb4ae4","serverName":"HoneyLabs Threat Intelligence","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T06:24:07.037Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":47,"error":null,"detail":{"tools":[{"name":"search_events_tool","description":"Return individual raw honeypot events with all fields. Use when the user wants to see\nactual records: 'show me events from this IP', 'what hit port 443 last wee"},{"name":"top_attackers_tool","description":"Ranked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top\nattacking countries', 'most targeted ports', 'most common user agents', 'top A"},{"name":"ioc_lookup_tool","description":"Look up any IP address, CIDR network, set of networks, or domain in the honeypot\n    dataset. Use this FIRST whenever the\n    user asks: 'is this IP malicious?'"},{"name":"cve_lookup_tool","description":"Who is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577\nbeing exploited in the wild?', 'who is scanning for this CVE?', 'show me act"},{"name":"payload_search_tool","description":"Literal substring search over captured request text: URL path, request body,\nrequest headers and event summary. Use for: 'find attacks targeting /wp-admin',\n'fi"},{"name":"attack_timeline_tool","description":"Attack volume over time, bucketed by hour or day. Use for: 'show attack trends this\nweek', 'was there a spike on port 22?', 'how has SSH scanning changed?', 'at"},{"name":"asn_enrich_tool","description":"Full honeypot profile for an ASN (autonomous system / hosting provider). Use for:\n'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks fro"},{"name":"fingerprint_search_tool","description":"Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks:\n'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?',"},{"name":"fingerprint_similar_tool","description":"Request shapes within a few headers of an Akin HTTP fingerprint, with what\nthose clients ask for and call themselves, plus the family the token belongs\nto. Use "},{"name":"fingerprint_population_tool","description":"The population behind a single client fingerprint: how many source IPs carry it,\nacross how many networks (ASNs) and countries, the ports they hit, the top netw"},{"name":"udp_activity_tool","description":"UDP datagrams sent to the sensors: DNS questions, QUIC client fingerprints and other\nUDP probes, with the ports, networks and countries involved. Use when a use"}],"toolCount":11,"toolsHash":"0e3ab4afe0feece7add6f846ba9bbf5eb3940d4f92c73999ec464f5c43fb4ae4","serverName":"HoneyLabs Threat Intelligence","capabilities":["tools"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}}],"tools":[{"name":"search_events_tool","description":"Return individual raw honeypot events with all fields. Use when the user wants to see\nactual records: 'show me events from this IP', 'what hit port 443 last wee"},{"name":"top_attackers_tool","description":"Ranked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top\nattacking countries', 'most targeted ports', 'most common user agents', 'top A"},{"name":"ioc_lookup_tool","description":"Look up any IP address, CIDR network, set of networks, or domain in the honeypot\n    dataset. Use this FIRST whenever the\n    user asks: 'is this IP malicious?'"},{"name":"cve_lookup_tool","description":"Who is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577\nbeing exploited in the wild?', 'who is scanning for this CVE?', 'show me act"},{"name":"payload_search_tool","description":"Literal substring search over captured request text: URL path, request body,\nrequest headers and event summary. Use for: 'find attacks targeting /wp-admin',\n'fi"},{"name":"attack_timeline_tool","description":"Attack volume over time, bucketed by hour or day. Use for: 'show attack trends this\nweek', 'was there a spike on port 22?', 'how has SSH scanning changed?', 'at"},{"name":"asn_enrich_tool","description":"Full honeypot profile for an ASN (autonomous system / hosting provider). Use for:\n'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks fro"},{"name":"fingerprint_search_tool","description":"Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks:\n'have you seen this JA4 fingerprint?', 'which IPs share this TLS fingerprint?',"},{"name":"fingerprint_similar_tool","description":"Request shapes within a few headers of an Akin HTTP fingerprint, with what\nthose clients ask for and call themselves, plus the family the token belongs\nto. Use "},{"name":"fingerprint_population_tool","description":"The population behind a single client fingerprint: how many source IPs carry it,\nacross how many networks (ASNs) and countries, the ports they hit, the top netw"},{"name":"udp_activity_tool","description":"UDP datagrams sent to the sensors: DNS questions, QUIC client fingerprints and other\nUDP probes, with the ports, networks and countries involved. Use when a use"}],"package":null,"toolSurface":{"id":"ts_wgkyz9wx33sa","endpointId":"ep_damdy6hpke86","hash":"0e3ab4afe0feece7add6f846ba9bbf5eb3940d4f92c73999ec464f5c43fb4ae4","toolCount":11,"serverName":"HoneyLabs Threat Intelligence","serverVersion":"1.0.0","protocolVersion":"2025-06-18","firstSeenAt":"2026-10-05T13:29:52.874Z","lastSeenAt":"2026-10-10T18:28:11.462Z","observations":20,"toolNames":["search_events_tool","top_attackers_tool","ioc_lookup_tool","cve_lookup_tool","payload_search_tool","attack_timeline_tool","asn_enrich_tool","fingerprint_search_tool","fingerprint_similar_tool","fingerprint_population_tool","udp_activity_tool"],"distinctSurfaces":6},"endpointFacts":[{"id":"ep_damdy6hpke86","url":"https://mcp.honeylabs.net/mcp","type":"mcp_streamable_http","factsCheckedAt":"2026-10-09T22:26:43.596Z","auth":{"observedAt":"2026-10-09T22:26:43.642Z","authRequired":false,"scheme":null,"resourceMetadata":{"url":"https://mcp.honeylabs.net/.well-known/oauth-protected-resource/mcp","resource":"https://mcp.honeylabs.net/mcp","authorizationServers":["https://mcp.honeylabs.net"],"scopesSupported":[]},"authorizationServer":{"url":"https://mcp.honeylabs.net/.well-known/oauth-authorization-server","issuer":"https://mcp.honeylabs.net","grantTypesSupported":["authorization_code"],"codeChallengeMethodsSupported":["S256"],"tokenEndpointAuthMethodsSupported":["none"],"dynamicClientRegistration":true,"dpopSigningAlgValuesSupported":[],"clientIdMetadataDocumentSupported":null},"conformance":{"dpop":false,"rfc8414":true,"rfc9728":true,"pkceS256":true,"clientIdMetadataDocument":false,"dynamicClientRegistration":true}},"tls":{"observedAt":"2026-10-09T22:26:43.677Z","protocol":"TLSv1.3","chainValid":true,"chainError":null,"hostMatches":true,"subject":"mcp.honeylabs.net","issuer":{"commonName":"YE2","organization":"Let's Encrypt"},"validFrom":"2026-08-24T20:13:30.000Z","validTo":"2026-11-22T20:13:29.000Z","daysToExpiry":42,"sanCount":1,"fingerprint256":"D6:07:B3:9C:4F:A4:D6:BC:79:5C:CE:69:F5:9F:12:D0:F2:A4:42:FA:8E:A8:1E:BE:75:B0:96:67:7E:3E:1D:F4"}}]},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"mcp_registry","key":"net.honeylabs/mcp","url":"https://registry.modelcontextprotocol.io/v0/servers/net.honeylabs%2Fmcp","firstSeenAt":"2026-09-07T08:19:34.702Z","fetchedAt":"2026-10-08T18:22:11.451Z","normalizedAt":"2026-10-08T18:22:11.451Z"}]},"firstSeenAt":"2026-09-07T08:19:34.702Z","updatedAt":"2026-10-10T18:30:16.797Z"}