Navigation

Changelog

The latest major releases of mlab.sh. Smaller fixes and improvements ship continuously and are not listed here.

Organization

Team roles

Decide who in your organization can do what.

  • Four roles: Owner, Admin, Member and Viewer.
  • Viewers can read everything but cannot run scans or change anything.
  • Admins manage members, API keys, webhooks and integrations; only the owner manages billing.
  • Change a member's role, remove a member, or transfer ownership from the team page.
Security

Active sessions

See every browser signed in to your account and sign out the ones you do not recognise.

  • Stay signed in on several devices at once.
  • Each session shows its browser, IP address and last activity.
  • Sign out a single session, or every session except the one you are using.
  • Changing your password now signs out all your other sessions.
Organization

Organization audit log

A record of who changed what in your organization.

  • Member invitations, API keys, MCP tokens, 2FA changes, webhooks, infrastructure and billing events in one timeline.
  • Filter by category and period, and export to CSV.
  • History of 7 days on Free, 30 days on Pro, 60 days on Team and Enterprise.
Workspace

New dashboard and unified scan history

One place for everything you and your team looked up.

  • Switch the dashboard between your own activity and your organization's.
  • A single scan history across every lookup type, with filters.
  • Team subscriptions show which member manages billing.
Reports

PDF reports

Download domain and RedKit results as ready-to-share PDF reports.

  • Same findings and score as the result page, laid out for reading and printing.
  • Consistent output whatever your browser or theme.
Organization

Team activity

See what your organization investigated, and who looked.

  • A feed of every lookup across the team, with the member on each line.
  • The indicators your team reached for most, and how many people looked at each.
  • Tells a paid scan apart from a result page that was only viewed.
Integrations

Outbound webhooks

Push mlab events to your own tools.

  • Native formats for Slack, Discord and Microsoft Teams, plus a signed generic JSON format.
  • Choose which events each endpoint receives.
  • Automatic retries, a delivery log and one-click replay of failed deliveries.
Investigations

Cases

Group the indicators of an investigation and discuss them with your team.

  • Add indicators to a case from any lookup page, or paste a list.
  • Comment on the case or on a single indicator.
  • Open and close cases as the investigation moves.
Monitoring

Domain watch and change detection

Know when a domain or an IP changes.

  • Domain and IP pages show what changed since the previous lookup.
  • Schedule recurring scans of any domain, including look-alikes of your brand and your suppliers.
  • Get an email or a webhook when a scheduled scan finds changes.
Integrations

Lookup exports

Take any lookup result into your tickets, spreadsheets and threat platforms.

  • Export as JSON, CSV, STIX 2.1 or MISP from every lookup page.
  • Indicators are defanged where it matters, so they are safe to paste.