Changelog
The latest major releases of mlab.sh. Smaller fixes and improvements ship continuously and are not listed here.
Team roles
Decide who in your organization can do what.
- Four roles: Owner, Admin, Member and Viewer.
- Viewers can read everything but cannot run scans or change anything.
- Admins manage members, API keys, webhooks and integrations; only the owner manages billing.
- Change a member's role, remove a member, or transfer ownership from the team page.
Active sessions
See every browser signed in to your account and sign out the ones you do not recognise.
- Stay signed in on several devices at once.
- Each session shows its browser, IP address and last activity.
- Sign out a single session, or every session except the one you are using.
- Changing your password now signs out all your other sessions.
Organization audit log
A record of who changed what in your organization.
- Member invitations, API keys, MCP tokens, 2FA changes, webhooks, infrastructure and billing events in one timeline.
- Filter by category and period, and export to CSV.
- History of 7 days on Free, 30 days on Pro, 60 days on Team and Enterprise.
New dashboard and unified scan history
One place for everything you and your team looked up.
- Switch the dashboard between your own activity and your organization's.
- A single scan history across every lookup type, with filters.
- Team subscriptions show which member manages billing.
PDF reports
Download domain and RedKit results as ready-to-share PDF reports.
- Same findings and score as the result page, laid out for reading and printing.
- Consistent output whatever your browser or theme.
Team activity
See what your organization investigated, and who looked.
- A feed of every lookup across the team, with the member on each line.
- The indicators your team reached for most, and how many people looked at each.
- Tells a paid scan apart from a result page that was only viewed.
Outbound webhooks
Push mlab events to your own tools.
- Native formats for Slack, Discord and Microsoft Teams, plus a signed generic JSON format.
- Choose which events each endpoint receives.
- Automatic retries, a delivery log and one-click replay of failed deliveries.
Cases
Group the indicators of an investigation and discuss them with your team.
- Add indicators to a case from any lookup page, or paste a list.
- Comment on the case or on a single indicator.
- Open and close cases as the investigation moves.
Domain watch and change detection
Know when a domain or an IP changes.
- Domain and IP pages show what changed since the previous lookup.
- Schedule recurring scans of any domain, including look-alikes of your brand and your suppliers.
- Get an email or a webhook when a scheduled scan finds changes.
Lookup exports
Take any lookup result into your tickets, spreadsheets and threat platforms.
- Export as JSON, CSV, STIX 2.1 or MISP from every lookup page.
- Indicators are defanged where it matters, so they are safe to paste.