mlab.sh started as a way to answer one question fast: is this IP, domain, hash or file something to worry about? It grew into a set of platforms covering investigation, attack surface, detection, governance and training, all behind one account.
An alert is only useful if someone can act on it. We would rather show three findings that matter than three hundred that do not.
Every verdict comes with what it is based on: the record, the header, the line of code. You should never have to take our word for it.
No tracking, no profiling, no resale. What you search and upload stays tied to your account and serves your investigation only.
Investigate threats, not noise.