Scry
Free IPv4 lookups against a distributed attacker-observation corpus.
我該用這個嗎
品質與安全性
發現項目(4)
- HIGH
- LOW在 scry_tool 中
- LOW在 scry_campaigns 中
- LOW在 scry_stats 中
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"scry": {
"url": "https://mcp.tunnelmind.ai/mcp"
}
}
}遠端端點
https://mcp.tunnelmind.ai/mcpstreamable-http它能做什麼
工具清單
工具(12)
🟢scry_stats
Returns aggregate Scry corpus telemetry: total observation count, distinct source IPs, first/last observation timestamps, last-24h activity, and per-protocol breakdowns. Useful as a liveness/density check before issuing per-IP queries — lets an agent decide whether the corpus has enough data to be authoritative. Use this tool when: - An agent is planning a multi-step investigation and wants to know if Scry has corpus density worth querying. - You want a 'corpus health' signal in a dashboard or report. Do NOT use this tool when: - You want details about a specific IP — use `scry_check`. - You want sensor fleet size or node identities — never exposed at any tier. Inputs: none. Returns: total_observations, distinct_source_ips, first_seen_ms, last_seen_ms, observations_last_24h, distinct_source_ips_last_24h, by_protocol, as_of_ms. Cost: free, anonymous, rate-limited. Latency: <100ms typical.
輸入結構描述
{
"type": "object",
"properties": {},
"additionalProperties": false
}🟢scry_check(ip)
Returns Scry's corpus knowledge for a single IPv4 address: when it was first/last observed, observation count, protocols and ports targeted, ASN, country, category (actor/scanner/not_observed), and confidence_bucket (low/medium/high). Use when an agent needs IP triage, hostility assessment, or risk signaling. Do NOT use for raw payloads (never exposed) or IPv6 (corpus is v4-only at v0.1).
輸入結構描述
{
"type": "object",
"properties": {
"ip": {
"type": "string",
"description": "IPv4 address (e.g. '8.8.8.8')"
}
},
"required": [
"ip"
],
"additionalProperties": false
}🟢scry_check_bulk(ips)
Look up many IPv4 addresses in one request. Up to 100 IPs per call. Same per-IP shape as scry_check, keyed by IP.
輸入結構描述
{
"type": "object",
"properties": {
"ips": {
"type": "array",
"items": {
"type": "string"
},
"minItems": 1,
"maxItems": 100
}
},
"required": [
"ips"
],
"additionalProperties": false
}⚪scry_top(dimension, since_ms, limit, include_noise)
Top-N source dimensions over a time window. Useful for situational awareness — 'where is the noise coming from right now?'
輸入結構描述
{
"type": "object",
"properties": {
"dimension": {
"type": "string",
"enum": [
"asn",
"country",
"protocol",
"port"
]
},
"since_ms": {
"type": "integer"
},
"limit": {
"type": "integer",
"minimum": 1,
"maximum": 100
},
"include_noise": {
"type": "boolean"
}
},
"additionalProperties": false
}🟢scry_timeseries(bucket, since_ms, until_ms)
Bucketed observation counts over time. Detect bursts, plot trends, sanity-check whether attacker activity is rising or falling.
輸入結構描述
{
"type": "object",
"properties": {
"bucket": {
"type": "string",
"enum": [
"minute",
"hour",
"day"
]
},
"since_ms": {
"type": "integer"
},
"until_ms": {
"type": "integer"
}
},
"additionalProperties": false
}⚪scry_asn(asn, since_ms)
Roll-up of corpus activity for a single ASN — observation count, distinct source IPs, actor count, scanner count, high-confidence actor count, and per-protocol breakdown.
輸入結構描述
{
"type": "object",
"properties": {
"asn": {
"type": "string"
},
"since_ms": {
"type": "integer"
}
},
"required": [
"asn"
],
"additionalProperties": false
}⚪scry_country(country, since_ms)
Roll-up of corpus activity by ISO country code. Same shape as scry_asn.
輸入結構描述
{
"type": "object",
"properties": {
"country": {
"type": "string",
"pattern": "^[A-Za-z]{2}$"
},
"since_ms": {
"type": "integer"
}
},
"required": [
"country"
],
"additionalProperties": false
}🟢scry_tools(protocol, since_ms, limit)
List detected attack tools — (protocol, payload, path) tuples sent by 3+ distinct source IPs. Aggregate metadata only; never lists member actors.
輸入結構描述
{
"type": "object",
"properties": {
"protocol": {
"type": "string"
},
"since_ms": {
"type": "integer"
},
"limit": {
"type": "integer",
"minimum": 1,
"maximum": 200
}
},
"additionalProperties": false
}⚪scry_tool(id)
Single tool detail by 16-char hex id from scry_tools.
輸入結構描述
{
"type": "object",
"properties": {
"id": {
"type": "string",
"pattern": "^[0-9a-f]{16}$"
}
},
"required": [
"id"
],
"additionalProperties": false
}⚪scry_campaigns(include_inactive, limit)
Active threat campaigns — coordinated attacker activity that exceeds the noise floor. ≥5 distinct actors, ≥3 ASNs, ≤5 destination ports, ≥1h history.
輸入結構描述
{
"type": "object",
"properties": {
"include_inactive": {
"type": "boolean"
},
"limit": {
"type": "integer",
"minimum": 1,
"maximum": 200
}
},
"additionalProperties": false
}⚪scry_campaign(id)
Single campaign detail by id (format: c[0-9a-f]{15}).
輸入結構描述
{
"type": "object",
"properties": {
"id": {
"type": "string",
"pattern": "^c[0-9a-f]{15}$"
}
},
"required": [
"id"
],
"additionalProperties": false
}⚪scry_recent(since_ms, limit, protocol, country, include_noise)
Recent observations feed — aggregated by source IP within a time window. Cursor-paginated via since_ms.
輸入結構描述
{
"type": "object",
"properties": {
"since_ms": {
"type": "integer"
},
"limit": {
"type": "integer",
"minimum": 1,
"maximum": 500
},
"protocol": {
"type": "string"
},
"country": {
"type": "string",
"pattern": "^[A-Za-z]{2}$"
},
"include_noise": {
"type": "boolean"
}
},
"additionalProperties": false
}社群
證據