image

MLAB.SH

IOC & File Intelligence Platform
Threat Intelligence

Analyze threats. Investigate faster. Decide with confidence.

Mlab.sh is a security investigation platform that lets you upload files, search IPs, domains, and hashes, then get structured, actionable intelligence in seconds. Built for SOC analysts, incident responders, blue teams, and security researchers who need fast, reliable threat analysis.

With 20+ specialized analysis tools, MITRE ATT&CK mapping, and a JavaScript deobfuscator built in, Mlab.sh centralizes your investigations so you can reduce manual correlation work and focus on what actually matters.

50K+

Files Analyzed

100K+

IOCs Searched

20+

Analysis Tools

<5s

Average Response Time

( How It Works )

From signal to decision in 5 steps

Collect

Feed Mlab with IPs, domains, hashes, or upload suspicious files (PNG, JPG, PDF, DOCX, XLSX, PPTX, EXE, DLL, SYS, up to 25 MB).

01

Analyze & Enrich

Mlab runs the data through 20+ specialized tools including MITRE ATT&CK mapping and JS deobfuscation to extract deep intelligence.

02

Correlate

Indicators are cross-referenced automatically to reveal hidden patterns, relationships, and attack chains.

03

Review

Get structured, human-readable results with no noise and no clutter. Everything you need to understand the threat at a glance.

04

Decide & Act

Make informed decisions based on reliable intelligence. Integrate findings into your incident response workflow.

05
Built for Security Teams

Key Capabilities

image

IOC Analysis

Search and enrich IPs, domains, and file hashes instantly. Cross-reference indicators across multiple intelligence sources.

image

File Intelligence

Upload and analyze suspicious files. Supports executables (EXE, DLL, SYS), documents (PDF, DOCX, XLSX, PPTX), and images (PNG, JPG).

image

MITRE ATT&CK Mapping

Automatically map findings to MITRE ATT&CK techniques and tactics for standardized threat classification.

image

JS Deobfuscator

Decode obfuscated JavaScript found in phishing pages, malicious documents, and web-based attacks.

image

Incident Response Platform

Self-hosted IR solution to coordinate and manage security incidents from detection to resolution.

( Mlab Incident Response )

From alert to resolution. On your infrastructure.

Most teams still manage incidents with shared docs, Slack threads and email chains. Mlab IR is a self-hosted incident response platform that turns security alerts into structured investigations, from triage to resolution, without relying on expensive enterprise SOAR solutions.

Ingest

Collect alerts from SIEMs, EDRs, email gateways, or any security tool via API integration.

01

Triage

Prioritize, deduplicate, and assign alerts with severity routing to the right analyst.

02

Investigate

Escalate alerts into cases. Attach evidence, track observables, and build investigation timelines.

03

Resolve

Document findings, close cases, generate reports, and capture lessons learned for future incidents.

04
Core Capabilities

Built for security teams, not project managers.

image

Alert Management

Ingest alerts from any source via API. Auto-deduplicate, enrich with context, assign severity, and route to the right analyst.

image

Case Management

Structure investigations with analyst assignment, priority tracking, and full audit trails from creation through closure.

image

Observable Tracking

Track IPs, domains, hashes, and emails across investigations. Identify recurring indicators and link related cases automatically.

image

Activity Timeline

Every action logged with timestamps. Complete traceability of status changes, comments, and evidence attachments.

image

Team & RBAC

Role-based access control with granular permissions for admins, analysts, and read-only viewers.

image

100% Self-Hosted

Your data never leaves your infrastructure. No SaaS dependency, no vendor lock-in. Deploy in under 5 minutes.