Skip to content
Official MCP RegistryListed

Scry

Free IPv4 lookups against a distributed attacker-observation corpus.

First seen 2 Oct 2026. Evidence as of 2 Oct 2026.

12
Tools
From an anonymous probe
1
Source listings
Each with its own history
0
Recorded changes
Since first seen

Tools

ToolDescriptionBehaviour
scry_asnRoll-up of corpus activity for a single ASN — observation count, distinct source IPs, actor count, scanner count, high-confidence actor count, and per-protocol breakdown.Not declared
scry_campaignSingle campaign detail by id (format: c[0-9a-f]{15}).Not declared
scry_campaignsActive threat campaigns — coordinated attacker activity that exceeds the noise floor. ≥5 distinct actors, ≥3 ASNs, ≤5 destination ports, ≥1h history.Not declared
scry_checkReturns Scry's corpus knowledge for a single IPv4 address: when it was first/last observed, observation count, protocols and ports targeted, ASN, country, category (actor/scanner/not_observed), and confidence_bucket (low/medium/high). Use when an agent needs IP triage, hostility assessment, or risk signaling. Do NOT use for raw payloads (never exposed) or IPv6 (corpus is v4-only at v0.1).Not declared
scry_check_bulkLook up many IPv4 addresses in one request. Up to 100 IPs per call. Same per-IP shape as scry_check, keyed by IP.Not declared
scry_countryRoll-up of corpus activity by ISO country code. Same shape as scry_asn.Not declared
scry_recentRecent observations feed — aggregated by source IP within a time window. Cursor-paginated via since_ms.Not declared
scry_statsReturns aggregate Scry corpus telemetry: total observation count, distinct source IPs, first/last observation timestamps, last-24h activity, and per-protocol breakdowns. Useful as a liveness/density check before issuing per-IP queries — lets an agent decide whether the corpus has enough data to be authoritative. Use this tool when: - An agent is planning a multi-step investigation and wants to know if Scry has corpus density worth querying. - You want a 'corpus health' signal in a dashboard or report. Do NOT use this tool when: - You want details about a specific IP — use `scry_check`. - You want sensor fleet size or node identities — never exposed at any tier. Inputs: none. Returns: total_observations, distinct_source_ips, first_seen_ms, last_seen_ms, observations_last_24h, distinct_source_ips_last_24h, by_protocol, as_of_ms. Cost: free, anonymous, rate-limited. Latency: <100ms typical.Not declared
scry_timeseriesBucketed observation counts over time. Detect bursts, plot trends, sanity-check whether attacker activity is rising or falling.Not declared
scry_toolSingle tool detail by 16-char hex id from scry_tools.Not declared
scry_toolsList detected attack tools — (protocol, payload, path) tuples sent by 3+ distinct source IPs. Aggregate metadata only; never lists member actors.Not declared
scry_topTop-N source dimensions over a time window. Useful for situational awareness — 'where is the noise coming from right now?'Not declared

Change history

No changes since the first observation. The first snapshot is the baseline.

Source listings
SourceListingFirst seenLast seenVersions
Official MCP Registryai.tunnelmind/scry2 Oct 20262 Oct 20261