Investigate threats, not noise.
The complete cyber platform - IOC & file intelligence, incident response, threat hunting and third-party risk, unified in one ecosystem. Built for SOC teams, DFIR and threat researchers who need signal, not noise.
🌐 mlab.sh · 🧭 Ecosystem · 📖 Docs · 🧰 Free tools · 𝕏 @Sn0wAlice
🔎 Core - mlab.sh
IOC & file intelligence. Drop in an IP, a domain, a hash, a certificate or a file and get back structured, actionable context - not a page of results to triage.
$ mlab scan domain sso-login-verify.example
DNS A 203.0.113.47 · AAAA 2001:db8::47 · no CNAME
Email SPF ~all · DKIM sig1 · DMARC missing
TLS Let's Encrypt · valid to 2026-10-24 · 2 issuers seen
Subdomains 4 found - mail, vpn, sso-portal · 1 flagged suspicious
Files no security.txt · robots.txt disallows /adminFiles go through static and dynamic analysis (EXE, DLL, PDF, Office…), infrastructure gets correlated, findings get mapped to MITRE ATT&CK. All of it available through the REST API, MCP and the CLI.
Rust-first, built in the open. Single static binaries, no daemon, no telemetry.
| Project | What it does |
|---|---|
| postmortem | Supply-chain scanner. Flags malicious install code, typosquats and shady provenance across your dependencies and your OS packages. Repo-reputation scoring, known-CVE intel. Node, Python, Rust, Ruby, PHP, Go, JVM |
| assay | Offline-first scanner for ML model artifacts - safetensors, GGUF, PyTorch pickle. Know what you just downloaded before you load it |
| mcpwn | Static security scanner for MCP servers. 36 rules over tool definitions - shadowed names, rug pulls, toxic data flows, dangerous capabilities. SARIF out |
| k3sec | Runtime security CLI for k3s clusters. eBPF syscall tracing and YARA detections merged into one live event stream |
Infra auditors - point them at an API, get graded findings back. Read-only (every request is a GET), snapshot & diff, CVEs matched to the exact installed version.
| Project | Audits |
|---|---|
| mlab-cloudflare | Cloudflare account - DNS, edge posture, TLS, Workers, Zero Trust, logging, IAM. One exit code for CI |
| mlab-scw | Scaleway account - IAM weaknesses, internet exposure, plaintext credentials, published CVEs |
| mlab-proxmox | Proxmox VE cluster - access control, firewall, guest isolation, backups, patch level |
| mlab-unifi | UniFi console - segmentation, firewall, Wi-Fi, exposure |
| mlab-mikrotik | MikroTik RouterOS - exposure, firewall, accounts |
Plug mlab.sh into the tools you already use.
SOC stack - enrich alerts with hash, URL, IP and CVE intel (KEV, EPSS, Tor), hand incidents to ir.mlab.sh.
| Integration | What it does |
|---|---|
| mlab-splunk | Splunk app - | mlab search command, adaptive response for Enterprise Security |
| mlab-wazuh | Drop-in integratord scripts and rules, no dependencies |
| shuffle-node | Shuffle SOAR app - IOC scanning & extraction, CVE and threat-actor data |
| n8n-nodes-mlab | Verified n8n community node - drop IOC enrichment into any workflow |
| mlab-glpi | GLPI 11 plugin - matches your inventory's installed software against CVEs, prioritises by KEV/EPSS/CVSS, opens tickets |
Dev & agents
| Integration | What it does |
|---|---|
| mlab-cli | Scan domains, IPs, files and URLs, extract IOCs, search CVEs and threat actors, gate CI on vulnerable dependencies. Terminal or JSON |
| VS Code · JetBrains | CVE scanning for your lockfiles (npm, Cargo, Go, Composer, Ruby, Python), prioritised with EPSS and CISA/EU KEV |
| MCP server | Give Claude, Cursor or any MCP client direct access to mlab.sh - scan IOCs and pull intel from inside your agent |
| Claude Code plugin | Ready-made SOC/DFIR and supply-chain skills - IOC triage, phishing, dependency review, SBOM audit |
| nav-ext | Chrome & Firefox extension. Highlights domain and IP IOCs on any page, pivot to an investigation in one click |
Security is not a product. It's a practice.
35 modules across governance, detection, attack surface, deception & endpoint and training. One data model, one API surface, one alerting pipeline. No silos, no gaps, no noise.
→ mlab.sh/ecosystem - the full, always up-to-date list.
- Bug reports / PRs → always welcome
- Questions → open an issue or ping @Sn0wAlice
Mlab · by Cyber Dream 🏴