Investigate threats, not noise.
The complete cyber platform - IOC & file intelligence, incident response, threat hunting and third-party risk, unified in one ecosystem. Built for SOC teams, DFIR and threat researchers who need signal, not noise.
🌐 mlab.sh · 🧭 Ecosystem · 📖 Docs · 🧰 Free tools · 𝕏 @Sn0wAlice
🔎 Core - mlab.sh
IOC & file intelligence. Drop in an IP, a domain, a hash, a certificate or a file and get back structured, actionable context - not a page of results to triage.
$ mlab scan domain sso-login-verify.example
DNS A 203.0.113.47 · AAAA 2001:db8::47 · no CNAME
Email SPF ~all · DKIM sig1 · DMARC missing
TLS Let's Encrypt · valid to 2026-10-24 · 2 issuers seen
Subdomains 4 found - mail, vpn, sso-portal · 1 flagged suspicious
Files no security.txt · robots.txt disallows /adminFiles go through static and dynamic analysis (EXE, DLL, PDF, Office…), infrastructure gets correlated, findings get mapped to MITRE ATT&CK. All of it available through the REST API, MCP and the CLI.
Rust-first, built in the open. Single static binaries, no daemon, no telemetry.
| Project | What it does |
|---|---|
| postmortem | Supply-chain scanner. Flags malicious install code, typosquats and shady provenance across your dependencies and your OS packages. Repo-reputation scoring, known-CVE intel. Node, Python, Rust, Ruby, PHP, Go, JVM |
| assay | Offline-first scanner for ML model artifacts - safetensors, GGUF, PyTorch pickle. Know what you just downloaded before you load it |
| mcpwn | Static security scanner for MCP servers. 36 rules over tool definitions - shadowed names, rug pulls, toxic data flows, dangerous capabilities. SARIF out |
| k3sec | Runtime security CLI for k3s clusters. eBPF syscall tracing and YARA detections merged into one live event stream |
Plug mlab.sh into the tools you already use.
| Integration | What it does |
|---|---|
| mlab-cli | Official command-line client for mlab.sh and the CVE API at vuln.mlab.sh |
| n8n-nodes-mlab | Verified n8n community node - drop IOC enrichment into any workflow |
| nav-ext | Chrome & Firefox extension. Highlights domain and IP IOCs on any page, pivot to an investigation in one click |
| VS Code | CVE scanning for your lockfiles, prioritised with EPSS and CISA KEV. Rescans on change, nothing leaves your machine until you agree |
| MCP server | Give Claude, Cursor or any MCP client direct access to mlab.sh - scan IOCs and pull intel from inside your agent |
Security is not a product. It's a practice.
35 modules across governance, detection, attack surface, deception & endpoint and training. One data model, one API surface, one alerting pipeline. No silos, no gaps, no noise.
→ mlab.sh/ecosystem - the full, always up-to-date list.
- Bug reports / PRs → always welcome
- Questions → open an issue or ping @Sn0wAlice
Mlab · by Cyber Dream 🏴