Skip to content
@mlab-sh

Mlab.sh

MLAB is a modular security analysis platform for IOC analysis at scale

🧪 MLAB

Investigate threats, not noise.

The complete cyber platform - IOC & file intelligence, incident response, threat hunting and third-party risk, unified in one ecosystem. Built for SOC teams, DFIR and threat researchers who need signal, not noise.

🌐 mlab.sh · 🧭 Ecosystem · 📖 Docs · 🧰 Free tools · 𝕏 @Sn0wAlice


🔎 Core - mlab.sh

IOC & file intelligence. Drop in an IP, a domain, a hash, a certificate or a file and get back structured, actionable context - not a page of results to triage.

$ mlab scan domain sso-login-verify.example

  DNS         A 203.0.113.47 · AAAA 2001:db8::47 · no CNAME
  Email       SPF ~all · DKIM sig1 · DMARC missing
  TLS         Let's Encrypt · valid to 2026-10-24 · 2 issuers seen
  Subdomains  4 found - mail, vpn, sso-portal · 1 flagged suspicious
  Files       no security.txt · robots.txt disallows /admin

Files go through static and dynamic analysis (EXE, DLL, PDF, Office…), infrastructure gets correlated, findings get mapped to MITRE ATT&CK. All of it available through the REST API, MCP and the CLI.


🧰 Open source

Rust-first, built in the open. Single static binaries, no daemon, no telemetry.

Project What it does
postmortem Supply-chain scanner. Flags malicious install code, typosquats and shady provenance across your dependencies and your OS packages. Repo-reputation scoring, known-CVE intel. Node, Python, Rust, Ruby, PHP, Go, JVM
assay Offline-first scanner for ML model artifacts - safetensors, GGUF, PyTorch pickle. Know what you just downloaded before you load it
mcpwn Static security scanner for MCP servers. 36 rules over tool definitions - shadowed names, rug pulls, toxic data flows, dangerous capabilities. SARIF out
k3sec Runtime security CLI for k3s clusters. eBPF syscall tracing and YARA detections merged into one live event stream

Infra auditors - point them at an API, get graded findings back. Read-only (every request is a GET), snapshot & diff, CVEs matched to the exact installed version.

Project Audits
mlab-cloudflare Cloudflare account - DNS, edge posture, TLS, Workers, Zero Trust, logging, IAM. One exit code for CI
mlab-scw Scaleway account - IAM weaknesses, internet exposure, plaintext credentials, published CVEs
mlab-proxmox Proxmox VE cluster - access control, firewall, guest isolation, backups, patch level
mlab-unifi UniFi console - segmentation, firewall, Wi-Fi, exposure
mlab-mikrotik MikroTik RouterOS - exposure, firewall, accounts

🔌 Integrations

Plug mlab.sh into the tools you already use.

SOC stack - enrich alerts with hash, URL, IP and CVE intel (KEV, EPSS, Tor), hand incidents to ir.mlab.sh.

Integration What it does
mlab-splunk Splunk app - | mlab search command, adaptive response for Enterprise Security
mlab-wazuh Drop-in integratord scripts and rules, no dependencies
shuffle-node Shuffle SOAR app - IOC scanning & extraction, CVE and threat-actor data
n8n-nodes-mlab Verified n8n community node - drop IOC enrichment into any workflow
mlab-glpi GLPI 11 plugin - matches your inventory's installed software against CVEs, prioritises by KEV/EPSS/CVSS, opens tickets

Dev & agents

Integration What it does
mlab-cli Scan domains, IPs, files and URLs, extract IOCs, search CVEs and threat actors, gate CI on vulnerable dependencies. Terminal or JSON
VS Code · JetBrains CVE scanning for your lockfiles (npm, Cargo, Go, Composer, Ruby, Python), prioritised with EPSS and CISA/EU KEV
MCP server Give Claude, Cursor or any MCP client direct access to mlab.sh - scan IOCs and pull intel from inside your agent
Claude Code plugin Ready-made SOC/DFIR and supply-chain skills - IOC triage, phishing, dependency review, SBOM audit
nav-ext Chrome & Firefox extension. Highlights domain and IP IOCs on any page, pivot to an investigation in one click

🧭 The ecosystem

Security is not a product. It's a practice.

35 modules across governance, detection, attack surface, deception & endpoint and training. One data model, one API surface, one alerting pipeline. No silos, no gaps, no noise.

→ mlab.sh/ecosystem - the full, always up-to-date list.


🤝 Get involved

  • Bug reports / PRs → always welcome
  • Questions → open an issue or ping @Sn0wAlice

Mlab · by Cyber Dream 🏴

Pinned Loading

  1. mlab-cli mlab-cli Public

    CLI for the mlab.sh threat-intelligence and CVE APIs: scan domains, IPs, files and URLs, pull IOCs out of text, gate CI on vulnerable dependencies, and search CVEs and threat actors. Single Rust bi…

    Rust 1

  2. postmortem postmortem Public

    Supply-chain scanner. Flags malicious install code, typosquats, and shady provenance across your dependencies and your OS packages. Repo-reputation scoring, known-CVE intel, no telemetry.

    Rust 10

  3. k3sec k3sec Public

    Runtime security CLI for k3s clusters, written in Rust.

    Rust 4

  4. apex apex Public

    Static analysis for Android/iOS packages (.apk, .aab, .xapk, .ipa) Extracts the package, runs 15 analyzers, and reports security findings with a weighted score.

    Rust 2

  5. mcpwn mcpwn Public

    Static security scanner for MCP (Model Context Protocol) servers.

    Rust 1

  6. vuln-scan-action vuln-scan-action Public

    Scan your lockfiles for known CVEs on every push or pull request, powered by vuln.mlab.sh. Auto-detects lockfiles, checks every dependency against OSV + Sonatype OSS Index, writes a job summary, an…

    TypeScript 1

Repositories

Showing 10 of 29 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…