Mlab - IOC & Threat Intelligence

by mlab-sh

259 downloads
Not rated
GitHub

About

Threat intelligence MCP server for SOC analysts, DFIR and security researchers. Scan and enrich IOCs directly from Claude, Cursor or any MCP client: IP addresses (IPv4/IPv6), domains, file hashes and blockchain addresses. Search CVEs by keyword, vendor or product, retrieve full C

Details

Author
mlab-sh
Downloads
259
Categories
Developer Tools, Security

- 17 tools covering IOC scanning, CVE search, and threat actors
- Auto-detect indicator type with detect_ioc
- Full domain scans and IP enrichment
- Reverse CVE lookup for threat actors
- Workspace bookmarks, scan history, and account info
- Remote server — no npm or Docker needed

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Mlab - IOC & Threat Intelligence
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

Configure your MCP client to point to the remote server URL https://mlab.sh/mcp and authenticate with a Mlab account (free tier available). For Claude Desktop, add the URL to claude_desktop_config.json under mcpServers. For Claude.ai (web), add it as a custom connector under Settings → Connectors. For other MCP clients, add a remote MCP server and authenticate.

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "mlab - ioc & threat intelligence": {
            "mlab": {
                "command": "npx",
                "args": [
                    "-y",
                    "mcp-remote",
                    "https://mlab.sh/mcp",
                    "--header",
                    "Authorization: Bearer mcp_xxx"
                ]
            }
        }
    }
}

McpServers

{
    "mlab": {
        "command": "npx",
        "args": [
            "-y",
            "mcp-remote",
            "https://mlab.sh/mcp",
            "--header",
            "Authorization: Bearer mcp_xxx"
        ]
    }
}

Mlab MCP Server

Bring real-time threat intelligence into your AI workflow. The Mlab MCP server connects Claude, Cursor, or any MCP-compatible client to mlab.sh — an IOC & file intelligence platform built for SOC analysts, DFIR teams and security researchers. Ask your AI assistant things like: - "Is this IP malicious? 45.155.xx.xx" - "Scan suspicious-domain.com and summarize the findings" - "Which threat actors are known to exploit CVE-2024-3400?" - "Search recent CVEs affecting Fortinet products" No local install required — Mlab is a remote MCP server. Zero npm, zero Docker, just a URL.

⚡ Quick Start

Server URL: https://mlab.sh/mcp

Claude Desktop

Add to your claude_desktop_config.json: ``json { "mcpServers": { "mlab": { "url": "https://mlab.sh/mcp" } } } `

Claude.ai (web)

Settings → Connectors → Add custom connector → paste
https://mlab.sh/mcp

Cursor / other MCP clients

Add a remote MCP server pointing to
https://mlab.sh/mcp and authenticate with your Mlab account (free tier available). 📖 Full setup guide: mlab.sh/helpcenter/integrations/mcp

🛠️ Available Tools (17)

IOC Scanning & Enrichment

| Tool | Description | |---|---| |
detect_ioc | Auto-detect the type of any indicator (IP, domain, hash…) and return relevant threat intel | | scan_ip | Threat intelligence lookup for IPv4 / IPv6 addresses | | start_domain_scan | Launch a full domain scan | | get_domain_scan_results | Retrieve domain scan results | | scan_crypto | Threat intelligence for blockchain addresses |

Vulnerability Intelligence

| Tool | Description | |---|---| |
cve_search | Search CVEs by keyword, product, vendor or CVE ID | | cve_detail | Full record for a specific CVE | | actors_by_cve | Reverse lookup — every threat actor known to exploit a given CVE |

Threat Actor Database

| Tool | Description | |---|---| |
search_actors | Free-text search across APTs and threat groups | | get_actor | Full actor profile — aliases, TTPs, campaigns |

Workspace

| Tool | Description | |---|---| |
add_bookmark / remove_bookmark / get_bookmarks | Save and manage IOCs of interest | | get_scan_history | Your recent scan activity | | get_scan_limits | Remaining scan quotas | | get_account_info | Account, organization & subscription info | | hello_world | Connectivity test |

💡 Example Workflows

Incident triage — paste a log excerpt and ask: "Extract the IOCs and check each one against Mlab". The assistant chains
detect_iocscan_ip / start_domain_scan and gives you a verdict per indicator. Vulnerability watch"Any critical CVEs on Palo Alto this month? Who exploits them?"cve_search + actors_by_cve. Threat actor research"Build me a one-page brief on APT28: TTPs, recent CVEs, aliases"search_actors + get_actor.

🔑 Authentication & Pricing

- Free tier — no credit card required: mlab.sh/auth/register - Quotas apply per organization (check anytime with
get_scan_limits`) - Pricing: mlab.sh/pricing

🔗 Links

- 🌐 Platform: mlab.sh - 📚 API docs: mlab.sh/developer/documentation - 🧩 Ecosystem (TPRM, IR, CVE tracking, threat hunting…): mlab.sh/ecosystem - 🆓 Free security tools: mlab.sh/tools --- Built by Mlab · Investigate threats, not noise.
No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.