HoneyLabs
Provides free per-IP lookups and an MCP API over a live honeypot dataset, showing internet scanning activity with TLS, HTTP, and SSH fingerprints and raw payloads.
A threat intelligence platform that provides free per-IP lookups and an MCP API over a live honeypot dataset, allowing users to see what is scanning the internet down to the payload. It solves the problem of understanding internet-wide scanning activity by offering searchable data on TLS, HTTP, and SSH fingerprints and raw probe payloads, with 90 days of history. The platform targets engineers, security teams, and developers who need real data for enrichment, investigation, or integration into their own tooling. It is delivered as a web interface, a REST API, and an MCP server, with integrations for common security tools like Splunk, Microsoft Sentinel, and MISP.
Key features
- Free per-IP lookups
- MCP API access
- Live honeypot dataset
- Searchable TLS, HTTP, SSH fingerprints
- Raw probe payload capture
- 90-day historical data
- CVE tracking with pre-disclosure detection
- Integrations with Splunk, Sentinel, Elastic, MISP, OpenCTI, CrowdSec
- No social media activity within the last 30 days
- Blog
- Marketplace
- API
- Docs
- Security teams
- Software developers
- DevOps sre teams