# HoneyLabs (slim) > HoneyLabs, an MCP server by honeylabs.net, listed from the official MCP registry. Indexed, not reviewed: facts and our own checks, no score or ranking. Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints. - Full: https://www.anchorterminal.com/tools/honeylabs-mcp.md (~1,400 tokens) · this version ~1,330 tokens · JSON https://www.anchorterminal.com/tools/honeylabs-mcp.json · canonical https://www.anchorterminal.com/tools/honeylabs-mcp - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 # HoneyLabs > Indexed, not reviewed: facts from the official MCP registry and our own checks. No score, grade or rank, and not in the rankings until the panel reviews it. How the index works: https://www.anchorterminal.com/indexed/ - Kind: MCP server, by honeylabs.net (https://honeylabs.net) - Listed because: It's published in the registry under honeylabs.net, a namespace the registry only gives to whoever proves they control that domain. - What the official MCP registry says: Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints. ## Facts - MCP registry: `net.honeylabs/mcp` 1.1.0 - Endpoint: https://mcp.honeylabs.net/mcp (streamable HTTP) - Source: https://github.com/honeylabshq/honeylabs-mcp - Website: https://honeylabs.net - GitHub stars: 2 - Registry entry updated: 2026-08-28 ## Tools - Tools it lists (10, about 3,154 tokens of context, `tools/list` without credentials, checked 2026-10-04 22:25 UTC): - `search_events_tool`: Return individual raw honeypot events with all fields. Use when the user wants to see actual records: 'show me events from this IP', 'what hit port 443 last… - `top_attackers_tool`: Ranked leaderboard of attack sources. Use for: 'who is attacking the most?', 'top attacking countries', 'most targeted ports', 'most common user agents', 'top… - `ioc_lookup_tool`: Look up any IP address, CIDR network, set of networks, or domain in the honeypot dataset. Use this FIRST whenever the user asks: 'is this IP malicious?', 'is… - `cve_lookup_tool`: Who is probing a specific CVE. Use whenever the user names a CVE: 'is CVE-2024-4577 being exploited in the wild?', 'who is scanning for this CVE?', 'show me… - `payload_search_tool`: Literal substring search over captured request text: URL path, request body, request headers and event summary. Use for: 'find attacks targeting /wp-admin',… - `attack_timeline_tool`: Attack volume over time, bucketed by hour or day. Use for: 'show attack trends this week', 'was there a spike on port 22?', 'how has SSH scanning changed?',… - `asn_enrich_tool`: Full honeypot profile for an ASN (autonomous system / hosting provider). Use for: 'tell me about AS202425', 'what is Vultr doing in my honeypots?', 'attacks… - `fingerprint_search_tool`: Search honeypot activity by TLS, HTTP, or SSH fingerprint. Use when a user asks: 'have you seen this JA4 fingerprint?', 'which IPs share this TLS… - `fingerprint_similar_tool`: Request shapes within a few headers of an Akin HTTP fingerprint, with what those clients ask for and call themselves, plus the family the token belongs to. Use… - `fingerprint_population_tool`: The population behind a single client fingerprint: how many source IPs carry it, across how many networks (ASNs) and countries, the ports they hit, the top… - How its tools read to an agent (0 errors, 21 warnings, 1 note, about 3,154 tokens; rules at https://www.anchorterminal.com/check.md; not part of the score): - warn TC07 ioc_lookup_tool: the description is about 532 tokens - warn TC11 asn_enrich_tool: none of its 3 parameters has a description - warn TC11 attack_timeline_tool: none of its 6 parameters has a description - warn TC11 cve_lookup_tool: none of its 3 parameters has a description - warn TC11 fingerprint_population_tool: none of its 2 parameters has a description - warn TC11 fingerprint_search_tool: none of its 5 parameters has a description - warn TC11 fingerprint_similar_tool: none of its 3 parameters has a description - warn TC11 ioc_lookup_tool: none of its 2 parameters has a description - warn TC11 payload_search_tool: none of its 4 parameters has a description - warn TC11 search_events_tool: none of its 17 parameters has a description - warn TC11 top_attackers_tool: none of its 7 parameters has a description - warn TC16 asn_enrich_tool: no readOnlyHint or destructiveHint - warn TC16 attack_timeline_tool: no readOnlyHint or destructiveHint - warn TC16 cve_lookup_tool: no readOnlyHint or destructiveHint - warn TC16 fingerprint_population_tool: no readOnlyHint or destructiveHint - warn TC16 fingerprint_search_tool: no readOnlyHint or destructiveHint - warn TC16 fingerprint_similar_tool: no readOnlyHint or destructiveHint - warn TC16 ioc_lookup_tool: no readOnlyHint or destructiveHint - warn TC16 payload_search_tool: no readOnlyHint or destructiveHint - warn TC16 search_events_tool: no readOnlyHint or destructiveHint - warn TC16 top_attackers_tool: no readOnlyHint or destructiveHint - note TC24 server: 10 of 10 tools have no outputSchema - JSON: https://www.anchorterminal.com/api/v1/tools/honeylabs-mcp.json - Being indexed says nothing about quality, and nobody can pay for it. Ask for a review: https://www.anchorterminal.com/builders/#claiming