Skip to content
Back to search
100
MCP v0.5.0 MCP 2025-03-26 streamable-http

Scry

ai.tunnelmind/scry

Free IPv4 lookups against a distributed attacker-observation corpus.

Uptime
75.0%
4 direct probes · 30d
Response
88ms
last probe
Tools
12
callable
Resources
0
readable
Prompts
1
available

Tools · 12

scry_stats

Returns aggregate Scry corpus telemetry: total observation count, distinct source IPs, first/last observation timestamps, last-24h activity, and per-protocol breakdowns. Useful as a liveness/density c…

scry_check

Returns Scry's corpus knowledge for a single IPv4 address: when it was first/last observed, observation count, protocols and ports targeted, ASN, country, category (actor/scanner/not_observed), and co…

scry_check_bulk

Look up many IPv4 addresses in one request. Up to 100 IPs per call. Same per-IP shape as scry_check, keyed by IP.

scry_top

Top-N source dimensions over a time window. Useful for situational awareness — 'where is the noise coming from right now?'

scry_timeseries

Bucketed observation counts over time. Detect bursts, plot trends, sanity-check whether attacker activity is rising or falling.

scry_asn

Roll-up of corpus activity for a single ASN — observation count, distinct source IPs, actor count, scanner count, high-confidence actor count, and per-protocol breakdown.

scry_country

Roll-up of corpus activity by ISO country code. Same shape as scry_asn.

scry_tools

List detected attack tools — (protocol, payload, path) tuples sent by 3+ distinct source IPs. Aggregate metadata only; never lists member actors.

scry_tool

Single tool detail by 16-char hex id from scry_tools.

scry_campaigns

Active threat campaigns — coordinated attacker activity that exceeds the noise floor. ≥5 distinct actors, ≥3 ASNs, ≤5 destination ports, ≥1h history.

scry_campaign

Single campaign detail by id (format: c[0-9a-f]{15}).

scry_recent

Recent observations feed — aggregated by source IP within a time window. Cursor-paginated via since_ms.

Prompts · 1

tunnelmind_analyst

TunnelMind analyst config bundle (system prompt + tool subset + response schema + attestation tiers). Scry-scoped by default — pass surface="data" or surface="sigil" to retarget. Inline Ed25519 signat…

How to use

Add to your Claude Desktop / Cursor / Cline MCP config:

{
  "mcpServers": {
    "scry": {
      "url": "https://mcp.tunnelmind.ai/mcp",
      "transport": "streamable-http"
    }
  }
}