Navigation
24+ MODULES ★ LIVE INTEL FREE · EU HOSTED
Security Investigation Platform

Search./Scan./Investigate.

Upload files, search IPs, domains or hashes.
structured, analyst-ready intelligence in seconds.

No install No credit card EU infrastructure REST API
Already have an account? Sign in
EU Hosted

European infrastructure, your data stays inside the EU.

Private by default

No tracking, no profiling, no data resale. Ever.

Self-hostable

Run it on your own stack, Docker deploy in under 5 minutes.

MCP Ready

Native integrations with Claude, GPT and n8n workflows.

What a result looks like

A graded report with findings you can act on, not a raw data dump. Here is a real one, on a domain built to fail.

Domain scan report
badssl.com
Completed
D 57 / 100
Findings · needs attention
2 high 2 medium 6 low 2 info
  • High Subdomain points at an unclaimed third-party service
  • Medium DMARC policy is set to none, mail is not enforced
  • Low No CAA record, any CA may issue a certificate
Mail F HTTP F TLS 1.2 DNSSEC Off CAA No MX 5 Lookalikes 4 SSL certs 5
IP intelligence
IP104.154.89.105
Country🇺🇸 United States
ISPGoogle LLC
ASNAS396982
Hosting
Sections
Domain & DNS3
Email5
Web & TLS3
Attack surface1

How mlab works

One indicator in, a structured answer out. Here is what runs in between.

Accepted input
>
IPDomainURLHash FileEmailPhoneMAC Crypto walletBash scriptEML
Modules running
  • DNS & passive DNS
  • RDAP & WHOIS
  • TLS chain & certificate history
  • Reputation & blocklists
  • Tor exit nodes
  • Hash lookup
  • CVE & vulnerability tracking
  • Threat actor database
Relationships surfaced
domain IP certificate lookalike ASN actor
What you walk away with
D 57 / 100
Graded findings by severity PDF export & shareable report Bookmarks & scan history Scheduled re-scans with Watchdog REST API, CLI and MCP

Built for real investigations.

Three things that land on a security team most weeks, and what mlab actually returns for each one.

Who runs these SOC analysts Incident responders Blue teams Researchers
01
Phishing analysis
SOC · level 1 triage

A user forwards a suspicious email. Drop the .eml in and mlab pulls apart the headers, the URLs and the attachments, then checks the sender infrastructure against what it already knows.

You get back
  • Full header chain with SPF, DKIM and DMARC verdicts
  • Every extracted URL, resolved and scored
  • Attachment hashes checked against known families
EML parserURL analysisReputation
02
IOC investigation
Incident response · live incident

The SIEM flags an address nobody recognises. Paste it in and you get the hosting picture and the history in one page, instead of six tabs and a copy-paste chain.

You get back
  • Geolocation, ISP, ASN and hosting classification
  • Passive DNS history and the domains sharing the host
  • Tor exit-node and blocklist status
IP lookupPassive DNSCorrelation
03
Malware triage
Blue team & research

A binary turns up on an endpoint and the question is whether it matters before anyone wakes up the on-call. Upload it and get a verdict you can put in a ticket.

You get back
  • YARA matches with the rule that fired
  • Hash reputation and previously seen samples
  • Behaviour mapped onto MITRE ATT&CK
File analysisYARAMITRE ATT&CK

What's under the hood

The short version, in numbers, and one real call so you can see the shape of what comes back.

Indicator types accepted 11
IP · domain · URL · hash · file · email · phone · MAC · wallet · bash · EML
RedKit scan modules 24+
Recon, vulnerability detection and compliance checks
Free tools, no account 23
Decoders, parsers, generators and cheat sheets
Ways in 4
Web app · REST API · CLI · MCP for AI agents
Report formats 3
Web report · PDF export · JSON over the API
Live response
$ curl -H "x-api-key: $MLAB_KEY" \
    https://mlab.sh/api/v1/scan/ip/45.33.32.156

{
  "ip": "45.33.32.156",
  "as": "AS63949 Akamai Connected Cloud",
  "isp": "Akamai Technologies, Inc.",
  "org": "Linode",
  "country": "United States",
  "region": "California",
  "city": "Fremont",
  "reserved": false,
  "status": "success"
}

Real output for the host behind scanme.nmap.org. The same call works from the CLI and from an MCP client.

Security & privacy first

What that means in practice, rather than as a claim.

Where it runs
European infrastructure, with European providers. Nothing is stored outside the EU.
What stays private
Uploaded files, your searches and your history are tied to your account and are never listed publicly. Pages that could carry personal data, email addresses, phone numbers and uploaded files, are excluded from search engines at the server, not by asking politely in a meta tag.
Account security
Two-factor with TOTP, passkeys over WebAuthn, and single sign-on for organisations. Recovery codes rather than a support ticket.
Reporting a vulnerability
A published security.txt with a direct channel. We would rather hear it from you than read about it.
Your data, your call
Retention is limited and purpose-bound under GDPR. The detail lives in the privacy policy, and a human answers on the contact page if it is not covered there.

One platform, multiple products

A growing suite of security tools designed to work together, from threat investigation to incident response.

Featured / Core
Platforms / self-hosted
mlab IR

Your alerts deserve a real workflow.

Self-hosted incident response platform. Turn security alerts into structured investigations, from triage to case closure, on your infrastructure.

Explore mlab IR
mlab TPRM

Your third-party risks deserve a real platform.

DORA-compliant third-party risk management platform. Manage ICT provider assessments, generate EBA-ready reports and meet DORA Pillar IV requirements.

Explore mlab TPRM
Tools / 4 live
vuln.mlab.sh

Search & explore CVEs with severity scores and affected products.

Explore
actors.mlab.sh

Indexed profiles of 500+ documented threat actors with aliases, origins & motivations.

Explore
hunt.mlab.sh

Proactive threat hunting using Sigma & YARA detection rules.

Explore
news.mlab.sh

Curated cybersecurity news, threat intelligence briefings and CVE alerts.

Explore

AI mlab.sh

Plug Claude, GPT or any MCP-compatible agent into mlab, or wire mlab into your n8n workflows with our official nodes. Run real investigations (lookup IOCs, search CVEs, profile threat actors) through one secure endpoint.

AI agent
Claude / GPT / Agent
tool: scan_ip 185.x.x.x
tool: cve_search CVE-2024-1234
tool: detect_ioc log snippet
MCP
mlab.sh
Intelligence engine
verdict: MALICIOUS · 12 sources
cvss: 9.8 · KEV listed
extracted: 7 IOCs · 3 IPs · 2 domains
scan_ip start_domain_scan detect_ioc cve_search scan_crypto get_scan_history

Start exploring mlab.

Create a free account or start analyzing IPs, domains, hashes and files right now. No credit card required.

$ mlab scan185.220.101.47
countryNL
asnAS9009 · M247
tagshosting
passive_dns3 records
verdictsuspicious
scan_time2.4s