Complete AI Training

MCP server · Security

HoneyLabs MCP server

by honeylabshq

Ask your AI whether an IP is a known scanner, what CVEs it probes, and who is attacking what.

Flow diagram: you ask your AI “Is 80.82.77.202 a known scanner?”, the HoneyLabs MCP server connects it to HoneyLabs, and you get back A short answer in your chat.

HoneyLabs is a threat intelligence service built from a network of honeypots. These are decoy computers placed on the internet that log every connection, handshake and request they receive. This MCP server lets your AI look up that data for you, so you can check an IP, a CVE or a fingerprint without visiting a website. It is handy for anyone who watches firewall logs, security alerts or suspicious traffic.

What is an MCP server? The 30-second version

On its own, your AI can only chat with you. An MCP server is a small helper program that gives your AI a new skill or a connection to an app or service. This one connects your AI to HoneyLabs, a honeypot sensor network that records what is scanning the internet. Once it is connected, your AI can look things up there and bring the answers back to you when you ask.

What this MCP server does

You ask your AI a question in plain words, like whether an IP is a known scanner. Your AI sends that question to this helper, which talks to the HoneyLabs service. HoneyLabs searches 90 days of probe data from its honeypot sensors and sends back the matching records. Your AI then turns that into a short answer in the chat, with the verdict, the ports, the paths and the fingerprints it found.

Flow diagram: you ask your AI “Is 80.82.77.202 a known scanner?”, the HoneyLabs MCP server connects it to HoneyLabs, and you get back A short answer in your chat. Click to zoom

What you can do with it

  • Check whether an IP or domain is known to be probing the internet
  • See the top attackers by IP, country, ASN, port or CVE
  • Search raw honeypot events with filters like port, protocol or fingerprint
  • Look up who is probing a named CVE and how often
  • Find shared infrastructure by TLS, HTTP or SSH fingerprint
  • Pull a full profile for an ASN, including top ports and countries
  • Search attack traffic by URL path or user-agent text

Try asking your AI

  • “Is 80.82.77.202 a known scanner? When was it last seen and what does it probe?”
  • “Pull every IP that hit port 445 with a non-Windows User-Agent in the last 24 hours.”
  • “Show CVE-2024-4577 probing volume per day for the last 7 days, broken down by ASN.”
  • “For the top 10 attackers on port 6379 right now, what TLS JA4 fingerprints do they share?”

What it gives back to you

You get answers in the chat, not raw files. Depending on what you ask, that can be a verdict on an IP, a ranked list of attackers, a table of events, a timeline of daily volume, or a profile of an ASN. Each row in a response counts as one credit against your daily limit. A free key gives you 500 credits a day.

Before you start

What you need

  • A free HoneyLabs key from honeylabs.net/dashboard (sign in with a magic link, no password)
  • An MCP client such as Claude Desktop, Claude Code, Cursor, Cline or Gemini CLI
  • Internet access to reach the HoneyLabs MCP endpoint

Good to know

The data is HoneyLabs' own record from its honeypots, so treat it as one strong clue rather than a final verdict, and keep an eye on your daily credit limit.

Install it with your AI

Add HoneyLabs MCP server to your AI, no technical skills needed

You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.

Sign in to get the install prompt

Members get a ready-made prompt that lets the Claude desktop app check HoneyLabs MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.

Sign in Become a member

Who it's for

Security analysts, IT admins and anyone who reads firewall logs or threat alerts and wants quick answers without leaving their AI chat.