Overview
Learn how mlab works, understand scan results, and explore the analysis modules available on the platform.
Learn how mlab works, understand scan results, and explore the different analysis modules available on the platform.
Need help or have a question? Please use our contact page.
Getting started
Unified Search
Paste any indicator and let mlab auto-detect its type and route you to the right module: IP, domain, hash, URL, email, phone, MAC, crypto or CVE.
Domain Scan
Understand how domain intelligence works and how to interpret infrastructure, DNS and SSL results.
File Scan
Learn how mlab analyzes files, extracts metadata, and runs format-specific analysis tools.
Email (EML) Scan
Inspect raw email files to analyze headers, authentication results, URLs and message content.
Crypto Address Lookup
Query blockchain addresses for labels, sanctions, risk scoring and classification across 18 chains.
MAC Address Lookup
Decode a MAC address offline: vendor, virtualization, randomization and the IPv6 address SLAAC would derive from it.
Email Lookup
Analyze an email address and its domain's anti-spoofing posture, mailbox type and known risk signals.
Phone Lookup
Validate a phone number in E.164 form: country, line type, allocated operator and scam-shape findings.
Mlab Tools
Mitre Map
Explore how mlab maps domain and file behaviors to the MITRE ATT&CK framework.
YARA Rule Builder
Build, preview and export YARA rules with the guided rule builder, now available on hunt.mlab.sh.
RedKit
Run advanced security scans on your verified domains with recon, vulnerability and compliance modules.
Integrations
API Guide
Integrate mlab into your workflows with the REST API. Authentication, rate limits, endpoints and examples.
MCP Integration
Connect Claude and other AI assistants to mlab.sh via the Model Context Protocol. Scan, query, and manage your account directly from a conversation.
n8n Integration
Bring mlab.sh scanning, CVE intelligence and threat-actor data into your n8n workflows with the official community nodes - no code required.
GitHub Action
Scan your lockfiles for known CVEs on every push or pull request, powered by vuln.mlab.sh. Fails the build or just reports on a severity threshold.
VS Code Extension
Scan your lockfiles for known CVEs on demand from inside VS Code. Manual by design, results server-side.
Browser Extension
Detect domain and IP IOCs on any web page and pivot to an mlab.sh investigation in one click. Chrome, Edge, Brave and Firefox.