Navigation
24+ MODULES ★ LIVE INTEL FREE · EU HOSTED
Security Investigation Platform

Search./Scan./Investigate.

Upload files, search IPs, domains or hashes.
structured, analyst-ready intelligence in seconds.

No install No credit card EU infrastructure REST API
Already have an account? Sign in
12K+ Scans today
24 Scan modules
Live Always fresh
99.94% Uptime
Files analysed +12.4%
0
IOCs searched +8.7%
0
Scan modules 24
Recon
Vuln
Comp.
Avg. response -6.2%
0

Global threat activity

A snapshot of hosting infrastructure, malware C2 nodes and phishing endpoints observed across the network.

Recent activity Simulated

What a result looks like

Every scan returns structured, analyst-ready intelligence · no raw data dumps.

Domain Scan Report
evil-update-cdn.net
Domain
evil-update-cdn.net
Related SSL
3
Scan date
2026-04-21
Status
Completed
IP Intelligence
IP185.220.101.47
Country🇳🇱 Netherlands
ISPM247 Europe
ASNAS9009
Hosting

How mlab works

A structured investigation workflow designed for real-world security operations.

1
Submit an indicator or file

Paste an IP, domain, hash, URL or upload a suspicious file. That's all it takes to start.

2
Automated analysis & enrichment

mlab queries multiple sources in parallel (reputation databases, passive DNS, WHOIS, sandbox engines and more) to build a complete picture.

3
Correlation across indicators

Results are cross-referenced to surface patterns, infrastructure reuse and hidden relationships between observables.

4
Review & act

Get structured, transparent results you can use immediately: escalate, block, document or feed back into your detection pipeline.

Designed for security professionals

01 / SOC
SOC analysts

Quickly triage alerts, investigate indicators, and validate threats with structured and enriched data.

02 / IR
Incident responders

Correlate domains, IPs and files during active incidents to accelerate containment and response.

03 / Blue team
Blue teams

Support detection engineering, investigations and post-incident analysis with reliable signals.

04 / Research
Security researchers

Explore infrastructure, indicators and relationships without black-box abstractions.

What's under the hood

Purpose-built modules that cover every stage of a security investigation.

01 / Enrichment
Multi-source enrichment

Aggregate data from reputation feeds, passive DNS, WHOIS, geolocation and threat intelligence in a single query.

02 / Files
YARA scanning

Run YARA rules against uploaded files to detect malware families, packers and known threat patterns.

03 / Graph
Indicator correlation

Automatically link IPs, domains, hashes and URLs to uncover shared infrastructure and campaign overlaps.

04 / Integration
REST API

Integrate mlab into your workflows with a full API. Automate lookups, submit files and retrieve results programmatically.

05 / Output
Structured reports

Every analysis produces a clean, consistent report you can share with your team or attach to a case.

06 / Scan
Infrastructure scanning

Run targeted security checks on your own domains with RedKit · 24 modules across recon, vulnerability detection and compliance.

Built for real investigations.

See how security teams use mlab in their daily operations, from triage to forensic deep-dives.

01 / Phishing
Phishing analysis

A user reports a suspicious email. Upload the .eml file: mlab extracts URLs, attachments, sender reputation and infrastructure links to confirm or dismiss the threat in minutes.

EML parsing URL analysis Reputation
02 / IOC
IOC investigation

Your SIEM flags a suspicious IP. Paste it into mlab to get geolocation, ASN, passive DNS history, open ports and cross-references with known threat campaigns.

IP lookup Passive DNS Correlation
03 / Malware
Malware triage

A suspicious binary is found on an endpoint. Upload it to mlab for YARA rule matching, hash reputation lookup and structured extraction. Get a verdict with MITRE ATT&CK tags in seconds.

File analysis YARA MITRE ATT&CK

Security & privacy first

Built with security-by-design principles and strict data protection practices.

Controlled access

Uploaded files, searches and results are private by default and never exposed publicly.

Secure processing

All analyses within controlled environments with strict isolation and monitoring.

GDPR compliant

Data retention is limited, purpose-driven and aligned with European regulatory requirements.

EU infrastructure

Operated on European infrastructure with security-focused providers and strong controls.

One platform, multiple products

A growing suite of security tools designed to work together, from threat investigation to incident response.

Featured / Core
Platforms / self-hosted
mlab IR

Your alerts deserve a real workflow.

Self-hosted incident response platform. Turn security alerts into structured investigations, from triage to case closure, on your infrastructure.

Explore mlab IR
mlab TPRM

Your third-party risks deserve a real platform.

DORA-compliant third-party risk management platform. Manage ICT provider assessments, generate EBA-ready reports and meet DORA Pillar IV requirements.

Explore mlab TPRM
Tools / 4 live
vuln.mlab.sh

Search & explore CVEs with severity scores and affected products.

Explore
actors.mlab.sh

Indexed profiles of 500+ documented threat actors with aliases, origins & motivations.

Explore
hunt.mlab.sh

Proactive threat hunting using Sigma & YARA detection rules.

Explore
news.mlab.sh

Curated cybersecurity news, threat intelligence briefings and CVE alerts.

Explore

AI mlab.sh

Plug Claude, GPT or any MCP-compatible agent into mlab — or wire mlab into your n8n workflows with our official nodes. Run real investigations (lookup IOCs, search CVEs, profile threat actors) through one secure endpoint.

AI agent
Claude / GPT / Agent
tool: scan_ip 185.x.x.x
tool: cve_search CVE-2024-1234
tool: detect_ioc log snippet
MCP
mlab.sh
Intelligence engine
verdict: MALICIOUS · 12 sources
cvss: 9.8 · KEV listed
extracted: 7 IOCs · 3 IPs · 2 domains
scan_ip start_domain_scan detect_ioc cve_search scan_crypto get_scan_history

Start exploring mlab.

Create a free account or start analyzing IPs, domains, hashes and files right now. No credit card required.

$ mlab scan185.220.101.47
countryNL
asnAS9009 · M247
tagshosting
passive_dns3 records
verdictsuspicious
scan_time2.4s