Incident Response  ·  Self-Hosted

Your alerts deserve
a real workflow.

Mlab IR turns scattered security alerts into structured investigations — enriched by nine intelligence sources and closed with the regulatory notification already filed. All on your own infrastructure.

IR.EXAMPLE.COM / TRIAGE LIVE TRIAGE 42 MY QUEUE 7 CASES 12 RESOLVED 238 Suspicious PowerShell on WS-042 crowdstrike · 2 obs. · 14:02 HIGH Beaconing to known C2 — 203.0.113.4 splunk · 5 obs. · 14:01 HIGH Unusual login geo — user alice@ azure-ad · 3 obs. · 13:58 MED Phishing — HR impersonation campaign proofpoint · 8 obs. · 13:31 MED NOTIFICATION CLOCK · INC-2026-0184 DORA Art. 19 — initial notification 01:47 LEFT OF 4H
9

Enrichment Sources

4

Regulatory Frameworks

<5min

To Deploy

100%

Self-Hosted

( Ingest )

Alerts in, from anything that speaks JSON.

One endpoint, your SIEM's field names rather than ours, and deduplication on a key you choose. No agent to roll out, no ETL project, no connector to wait for.

Splunk CrowdStrike SentinelOne Elastic Wazuh Microsoft Sentinel Defender Proofpoint anything with a webhook
( Enrichment )

One indicator, nine opinions, one verdict.

An observable arrives as a value and nothing else. Every source you enable is asked at once, and the answers merge into a single verdict with each source still readable underneath.

mlab.sh VirusTotal AbuseIPDB GreyNoise urlscan.io AlienVault OTX Shodan MISP Have I Been Pwned

Asked in parallel

Every enabled source fires at once rather than in a queue, so the wait is the slowest source, not the sum of all of them.

Routed by type

A grid decides who answers for addresses, domains, hashes and the rest, with on-demand and automatic as separate switches so a rate-limited key stays useful.

Or your own source

Any REST API returning JSON: a URL template, an auth header and a few JSON paths. No code, no rebuild, no waiting on a vendor roadmap.

( Workflow )

From alert to resolution, in five stages.

STAGE 01

Ingest

One endpoint. Your SIEM's field names, not ours. Deduplicated on a key you choose, enriched before an analyst ever opens it.

STAGE 02

Triage

Every alert arrives with its enrichment verdict already attached. Decide, then escalate or close with a reason that is recorded rather than implied.

STAGE 03

Investigate

Cases with tasks, a shared timeline, hashed evidence and correlation across every past investigation. Recurring observables link themselves.

STAGE 04

Respond

A named incident commander, the NIST phases, and the DORA, NIS2 or GDPR clock started automatically the moment the incident is declared.

STAGE 05

Close & review

A PDF dossier, a scored post-incident review, and action items with a due date. Hot review at five days, cold at 180.

( Regulatory )

The clock starts when the incident does.

Assign a framework to an incident and every notification it requires is created with its deadline already calculated. Overdue ones surface on the dashboard instead of in someone's memory.

Framework
What it covers
Deadlines tracked
DORAArt. 19
Major ICT-related incidents, for financial entities in scope.
4h initial 72h intermediate 30d final
NIS2Art. 23
Significant incidents, notified to the authority and to the CSIRT.
24h early warning 72h notification
GDPRArt. 33
Personal data breaches, notified to the supervisory authority.
72h notification
ISO 27001A.5.24 – A.5.28
Incident management evidence for certification and surveillance audits.
audit trail

Registers you can export

The DORA ICT incident register and the GDPR violations register, as JSON or CSV, with classification, costs and notification history intact.

Numbers for the board

MTTD, MTTR, noisiest sources and an append-only audit trail. Live dashboards instead of a spreadsheet rebuilt every quarter.

Reviews that close the loop

Each NIST phase scored, action items carrying the change request that implemented them. The report writes itself at closure.

MITRE ATT&CK

Coverage you can defend in a meeting.

Tag cases with techniques and Mlab IR builds a heat-map across the matrix — every cell tells you how many cases hit it, and when. Detection gaps stop being an opinion and become a coordinate.

TECHNIQUE HEAT-MAP · LAST 90 DAYS INITIAL ACCESS EXECUTION PERSIST. LATERAL C2 T1566 · 24 T1190 · 6 T1078 · 13 T1059 · 17 T1204 · 3 T1218 · 8 T1547 · 4 T1053 · 11 T1543 · 0 T1021 · 7 T1550 · 0 T1570 · 2 T1071 T1573 T1090 DETECTION GAPS 3 techniques seen in cases, 0 detections in the SIEM T1543 · T1550 · T1556 Matrix coverage 75%
( Deployment )

SOAR features, without the SOAR price tag.

Enterprise SOAR vendors charge six figures. Spreadsheets cost zero but lose every thread. Mlab IR sits between — a proper platform you actually own.

Your infrastructure

Runs entirely on your servers. The only call that is always on is an hourly license HMAC carrying the tier, a timestamp and a nonce. No alert, case, observable or evidence ever leaves your network.

Five minutes to running

docker compose up and you are done. No agents, no ETL, no consulting hours to book. Bring your own MySQL and ClickHouse if you prefer.

No vendor lock-in

A REST API for everything, exports as CSV, JSON, JSONL or Markdown. Take your data out any time, with no exit fee and no migration tool to buy.

Free tier, not a trial

3 users, 10 alerts a month, 5 cases and 50 observables. The whole platform is there — only the monthly caps differ, and upgrading is a licence change with no reinstall.

Offline grace

Up to 48 hours at a time without outbound HTTPS. Beyond that the instance locks until the licence check succeeds again. Air-gapped deployments are a conversation, not a checkbox.

Account security

Password plus a second factor, TOTP or a WebAuthn passkey, with server-side sessions and a switch to force enrolment across a whole workspace.

Ready to fix your incident workflow?

Free tier included, no credit card, up and running in under five minutes.