Search./Scan./Investigate.
Upload files, search IPs, domains or hashes.
structured, analyst-ready intelligence in seconds.
Search in mlab.sh
Or upload a file to analyse
By searching or submitting files, you agree to our Terms of Service and Privacy Policy.
EU Hosted
European infrastructure, your data stays inside the EU.
Private by default
No tracking, no profiling, no data resale. Ever.
Self-hostable
Run it on your own stack, Docker deploy in under 5 minutes.
MCP Ready
Native integrations with Claude, GPT and n8n workflows.
What a result looks like
A graded report with findings you can act on, not a raw data dump. Here is a real one, on a domain built to fail.
How mlab works
One indicator in, a structured answer out. Here is what runs in between.
- DNS & passive DNS
- RDAP & WHOIS
- TLS chain & certificate history
- Reputation & blocklists
- Tor exit nodes
- Hash lookup
- CVE & vulnerability tracking
- Threat actor database
Built for real investigations.
Three things that land on a security team most weeks, and what mlab actually returns for each one.
Phishing analysis
SOC · level 1 triage
A user forwards a suspicious email. Drop the .eml in and mlab
pulls apart the headers, the URLs and the attachments, then checks the
sender infrastructure against what it already knows.
- Full header chain with SPF, DKIM and DMARC verdicts
- Every extracted URL, resolved and scored
- Attachment hashes checked against known families
IOC investigation
Incident response · live incidentThe SIEM flags an address nobody recognises. Paste it in and you get the hosting picture and the history in one page, instead of six tabs and a copy-paste chain.
- Geolocation, ISP, ASN and hosting classification
- Passive DNS history and the domains sharing the host
- Tor exit-node and blocklist status
Malware triage
Blue team & researchA binary turns up on an endpoint and the question is whether it matters before anyone wakes up the on-call. Upload it and get a verdict you can put in a ticket.
- YARA matches with the rule that fired
- Hash reputation and previously seen samples
- Behaviour mapped onto MITRE ATT&CK
What's under the hood
The short version, in numbers, and one real call so you can see the shape of what comes back.
$ curl -H "x-api-key: $MLAB_KEY" \
https://mlab.sh/api/v1/scan/ip/45.33.32.156
{
"ip": "45.33.32.156",
"as": "AS63949 Akamai Connected Cloud",
"isp": "Akamai Technologies, Inc.",
"org": "Linode",
"country": "United States",
"region": "California",
"city": "Fremont",
"reserved": false,
"status": "success"
}
Real output for the host behind scanme.nmap.org.
The same call works from the CLI and from an MCP client.
Security & privacy first
What that means in practice, rather than as a claim.
- Where it runs
- European infrastructure, with European providers. Nothing is stored outside the EU.
- What stays private
- Uploaded files, your searches and your history are tied to your account and are never listed publicly. Pages that could carry personal data, email addresses, phone numbers and uploaded files, are excluded from search engines at the server, not by asking politely in a meta tag.
- Account security
- Two-factor with TOTP, passkeys over WebAuthn, and single sign-on for organisations. Recovery codes rather than a support ticket.
- Reporting a vulnerability
- A published security.txt with a direct channel. We would rather hear it from you than read about it.
- Your data, your call
- Retention is limited and purpose-bound under GDPR. The detail lives in the privacy policy, and a human answers on the contact page if it is not covered there.
One platform, multiple products
A growing suite of security tools designed to work together, from threat investigation to incident response.
mlab.sh
Security investigation platform for SOC analysts, incident responders and security researchers. Analyze IPs, domains, hashes, URLs and files. Structured intelligence in seconds.
Explore mlabmlab IR
Your alerts deserve a real workflow.
Self-hosted incident response platform. Turn security alerts into structured investigations, from triage to case closure, on your infrastructure.
Explore mlab IRmlab TPRM
Your third-party risks deserve a real platform.
DORA-compliant third-party risk management platform. Manage ICT provider assessments, generate EBA-ready reports and meet DORA Pillar IV requirements.
Explore mlab TPRMactors.mlab.sh
Indexed profiles of 500+ documented threat actors with aliases, origins & motivations.
ExploreAI ↔ mlab.sh
Plug Claude, GPT or any MCP-compatible agent into mlab, or wire mlab into your n8n workflows with our official nodes. Run real investigations (lookup IOCs, search CVEs, profile threat actors) through one secure endpoint.
Start exploring mlab.
Create a free account or start analyzing IPs, domains, hashes and files right now. No credit card required.