Analyze threats.
Decide in seconds.
Mlab.sh is a security investigation platform for SOC analysts and incident responders. Upload files, search IOCs, map findings to MITRE ATT&CK, and coordinate response — all in one place.
Indicator Types
Free Tools, No Account
Scan & Analysis Modules
Avg. Response Time
Eleven indicator types, one platform.
Feed any IOC into Mlab and get enriched, correlated intelligence in seconds. Hashes are pivoted across sandboxes, IPs across passive DNS, domains across WHOIS and reputation feeds.
Supported file types · up to 10 MB
24+ modules, one workflow.
Stop juggling tabs across CyberChef, VT, AnyRun and grep. Every tool is wired into the same investigation graph so pivots happen automatically.
Every finding mapped to a technique.
Mlab automatically classifies behaviors against MITRE ATT&CK tactics and techniques. Compare reports across investigations, spot recurring TTPs, and feed your detection-engineering backlog.
Scan your own attack surface.
RedKit turns a domain into a graded report: 24+ recon, vulnerability and compliance modules covering DNS, mail, TLS and exposed surface. Misconfigurations and exposed services come back with remediation guidance, not just a list of ports.
Domain & DNS
Records, DNSSEC, CAA, subdomain takeover candidates and lookalike domains registered against you.
Email posture
SPF, DKIM and DMARC policy strength — including the DMARC set to none that nobody ever enforced.
Web & TLS
Certificate chain, protocol versions, security headers and the HTTP surface as an attacker enumerates it.
A graded verdict
One letter grade and a score out of 100, with findings bucketed high / medium / low / info so triage is obvious.
On a schedule
Re-run a scan on a cadence and watch the grade move, rather than discovering drift at the next audit.
Exportable
Web report, PDF export or JSON over the API. The same findings, in whichever form the reader needs.
Four ways in. Including your AI agent.
The web app is one interface out of four. Everything is reachable over a REST API with webhooks, from the CLI, and through a native MCP server — so Claude, GPT or any MCP-compatible agent can run real investigations against your tenant. Official n8n community nodes wire the same calls into your automation.
$ curl -H "x-api-key: $MLAB_KEY" \
https://mlab.sh/api/v1/scan/ip/45.33.32.156
{
"ip": "45.33.32.156",
"as": "AS63949 Akamai Connected Cloud",
"isp": "Akamai Technologies, Inc.",
"org": "Linode",
"country": "United States",
"region": "California",
"city": "Fremont",
"reserved": false,
"status": "success"
}
The same call works from the CLI and from an MCP client.
One platform, several products.
Mlab.sh is the investigation core. Two self-hosted platforms extend it into response and governance, and four free intelligence services sit alongside.
Mlab IR
Alerts, cases, incidents and evidence on your own infrastructure — with the DORA, NIS2 and GDPR notification clocks running automatically.
Explore Mlab IRMlab TPRM
DORA Pillar IV third-party risk: ICT provider registry, five-dimension scoring, contracts and the 15 EBA ITS templates.
Explore Mlab TPRMvuln.mlab.sh
Search and explore CVEs with severity scores and affected products.
actors.mlab.sh
Indexed profiles of 500+ documented threat actors, with aliases, origins and motivations.
hunt.mlab.sh
Proactive threat hunting with Sigma and YARA detection rules.
news.mlab.sh
Curated cybersecurity news, threat intelligence briefings and CVE alerts.
Start investigating in the next five minutes.
Free account, EU-hosted, no credit card. Or talk to us about deploying the self-hosted platforms alongside an audit.