Skip to content
@mlab-sh

Mlab.sh

MLAB is a modular security analysis platform for IOC analysis at scale

🧪 MLAB

Investigate threats, not noise.

The complete cyber platform - IOC & file intelligence, incident response, threat hunting and third-party risk, unified in one ecosystem. Built for SOC teams, DFIR and threat researchers who need signal, not noise.

🌐 mlab.sh · 🧭 Ecosystem · 📖 Docs · 🧰 Free tools · 𝕏 @Sn0wAlice


🔎 Core - mlab.sh

IOC & file intelligence. Drop in an IP, a domain, a hash, a certificate or a file and get back structured, actionable context - not a page of results to triage.

$ mlab scan domain sso-login-verify.example

  DNS         A 203.0.113.47 · AAAA 2001:db8::47 · no CNAME
  Email       SPF ~all · DKIM sig1 · DMARC missing
  TLS         Let's Encrypt · valid to 2026-10-24 · 2 issuers seen
  Subdomains  4 found - mail, vpn, sso-portal · 1 flagged suspicious
  Files       no security.txt · robots.txt disallows /admin

Files go through static and dynamic analysis (EXE, DLL, PDF, Office…), infrastructure gets correlated, findings get mapped to MITRE ATT&CK. All of it available through the REST API, MCP and the CLI.


🧰 Open source

Rust-first, built in the open. Single static binaries, no daemon, no telemetry.

Project What it does
postmortem Supply-chain scanner. Flags malicious install code, typosquats and shady provenance across your dependencies and your OS packages. Repo-reputation scoring, known-CVE intel. Node, Python, Rust, Ruby, PHP, Go, JVM
assay Offline-first scanner for ML model artifacts - safetensors, GGUF, PyTorch pickle. Know what you just downloaded before you load it
mcpwn Static security scanner for MCP servers. 36 rules over tool definitions - shadowed names, rug pulls, toxic data flows, dangerous capabilities. SARIF out
k3sec Runtime security CLI for k3s clusters. eBPF syscall tracing and YARA detections merged into one live event stream

Infra auditors - point them at an API, get graded findings back. Read-only (every request is a GET), snapshot & diff, CVEs matched to the exact installed version.

Project Audits
mlab-cloudflare Cloudflare account - DNS, edge posture, TLS, Workers, Zero Trust, logging, IAM. One exit code for CI
mlab-scw Scaleway account - IAM weaknesses, internet exposure, plaintext credentials, published CVEs
mlab-proxmox Proxmox VE cluster - access control, firewall, guest isolation, backups, patch level
mlab-unifi UniFi console - segmentation, firewall, Wi-Fi, exposure
mlab-mikrotik MikroTik RouterOS - exposure, firewall, accounts

🔌 Integrations

Plug mlab.sh into the tools you already use.

SOC stack - enrich alerts with hash, URL, IP and CVE intel (KEV, EPSS, Tor), hand incidents to ir.mlab.sh.

Integration What it does
mlab-splunk Splunk app - | mlab search command, adaptive response for Enterprise Security
mlab-wazuh Drop-in integratord scripts and rules, no dependencies
shuffle-node Shuffle SOAR app - IOC scanning & extraction, CVE and threat-actor data
n8n-nodes-mlab Verified n8n community node - drop IOC enrichment into any workflow
mlab-glpi GLPI 11 plugin - matches your inventory's installed software against CVEs, prioritises by KEV/EPSS/CVSS, opens tickets

Dev & agents

Integration What it does
mlab-cli Scan domains, IPs, files and URLs, extract IOCs, search CVEs and threat actors, gate CI on vulnerable dependencies. Terminal or JSON
VS Code · JetBrains CVE scanning for your lockfiles (npm, Cargo, Go, Composer, Ruby, Python), prioritised with EPSS and CISA/EU KEV
MCP server Give Claude, Cursor or any MCP client direct access to mlab.sh - scan IOCs and pull intel from inside your agent
Claude Code plugin Ready-made SOC/DFIR and supply-chain skills - IOC triage, phishing, dependency review, SBOM audit
nav-ext Chrome & Firefox extension. Highlights domain and IP IOCs on any page, pivot to an investigation in one click

🧭 The ecosystem

Security is not a product. It's a practice.

35 modules across governance, detection, attack surface, deception & endpoint and training. One data model, one API surface, one alerting pipeline. No silos, no gaps, no noise.

→ mlab.sh/ecosystem - the full, always up-to-date list.


🤝 Get involved

  • Bug reports / PRs → always welcome
  • Questions → open an issue or ping @Sn0wAlice

Mlab · by Cyber Dream 🏴

Pinned Loading

  1. mlab-cli mlab-cli Public

    CLI for the mlab.sh threat-intelligence and CVE APIs: scan domains, IPs, files and URLs, pull IOCs out of text, gate CI on vulnerable dependencies, and search CVEs and threat actors. Single Rust bi…

    Rust 1

  2. postmortem postmortem Public

    Supply-chain scanner. Flags malicious install code, typosquats, and shady provenance across your dependencies and your OS packages. Repo-reputation scoring, known-CVE intel, no telemetry.

    Rust 10

  3. k3sec k3sec Public

    Runtime security CLI for k3s clusters, written in Rust.

    Rust 4

  4. apex apex Public

    Static analysis for Android/iOS packages (.apk, .aab, .xapk, .ipa) Extracts the package, runs 15 analyzers, and reports security findings with a weighted score.

    Rust 2

  5. mcpwn mcpwn Public

    Static security scanner for MCP (Model Context Protocol) servers.

    Rust 1

  6. vuln-scan-action vuln-scan-action Public

    Scan your lockfiles for known CVEs on every push or pull request, powered by vuln.mlab.sh. Auto-detects lockfiles, checks every dependency against OSV + Sonatype OSS Index, writes a job summary, an…

    TypeScript 1

Repositories

Showing 10 of 28 repositories
  • .github Public
    mlab-sh/.github's past year of commit activity
    1 0 0 0 Updated Sep 30, 2026
  • vuln-scan-vscode Public

    VS Code extension to scan lockfiles for known CVEs (npm, Cargo, Go, Composer, Ruby, Python). EPSS scores, CISA/EU KEV exploited status, Problems panel diagnostics, CVE hover and IOC lookup. Powered by mlab.sh

    mlab-sh/vuln-scan-vscode's past year of commit activity
    TypeScript 1 MIT 0 0 0 Updated Sep 30, 2026
  • mlab-glpi Public

    GLPI 11 plugin: vulnerability management for your IT inventory. Matches installed software versions (Windows & Linux) against CVEs with vuln.mlab.sh, prioritizes by CISA KEV, EPSS and CVSS, and opens tickets automatically.

    mlab-sh/mlab-glpi's past year of commit activity
    PHP 0 MIT 0 0 0 Updated Sep 27, 2026
  • mlab-cli Public

    CLI for the mlab.sh threat-intelligence and CVE APIs: scan domains, IPs, files and URLs, pull IOCs out of text, gate CI on vulnerable dependencies, and search CVEs and threat actors. Single Rust binary, terminal or JSON.

    mlab-sh/mlab-cli's past year of commit activity
    Rust 1 GPL-3.0 0 0 0 Updated Sep 27, 2026
  • mlab-splunk Public

    Splunk app for mlab.sh: enrich events with file-hash, URL, IP and CVE threat intelligence (KEV, EPSS, Tor) via a | mlab search command, and send alerts to ir.mlab.sh for incident response. Works with Enterprise Security as an adaptive response.

    mlab-sh/mlab-splunk's past year of commit activity
    Python 0 MIT 0 0 0 Updated Sep 27, 2026
  • mlab-wazuh Public

    Wazuh integration for mlab.sh: enrich alerts with file-hash, URL, IP and CVE threat intelligence (KEV, EPSS, Tor), and forward them to ir.mlab.sh for incident response. Drop-in integratord scripts and rules, no dependencies.

    mlab-sh/mlab-wazuh's past year of commit activity
    Python 0 MIT 0 0 0 Updated Sep 27, 2026
  • shuffle-node Public

    Shuffle SOAR app for mlab.sh: domain, IP, hash, URL, email, phone and crypto scanning, IOC extraction, CVE intelligence and threat-actor data.

    mlab-sh/shuffle-node's past year of commit activity
    Python 0 MIT 0 0 0 Updated Sep 27, 2026
  • mcpwn Public

    Static security scanner for MCP (Model Context Protocol) servers.

    mlab-sh/mcpwn's past year of commit activity
    Rust 1 0 0 0 Updated Sep 26, 2026
  • mlab-sh/n8n-nodes-mlab's past year of commit activity
    TypeScript 0 MIT 0 0 0 Updated Sep 25, 2026
  • postmortem Public

    Supply-chain scanner. Flags malicious install code, typosquats, and shady provenance across your dependencies and your OS packages. Repo-reputation scoring, known-CVE intel, no telemetry.

    mlab-sh/postmortem's past year of commit activity
    Rust 10 GPL-3.0 0 0 0 Updated Sep 25, 2026

People

This organization has no public members. You must be a member to see who’s a part of this organization.