mlab.sh
Threat intelligence: enrich IOCs (IP, domain, URL, hash), search CVEs and actors, scan SBOMs
Install
Install and configure the MCP from https://doc.mlab.sh/docs/mlab.sh/integrations/mcp now. Follow the documentation's installation instructions, ask me for anything you can't complete yourself, and verify its tools load.Search⌘``K
Getting Started
Verify Your Infrastructure API Guide
Scans & Lookups
Unified Search Domain intelligence File analysis & content inspection Email (EML) Analysis Crypto Address Lookup MAC Address Lookup Email Lookup Phone Number Lookup Custom Scan
Developer API
Integrations
Overview MCP Integration n8n Integration GitHub Action VS Code Extension Browser Extension
Tools
Mitre Coverage Map YARA Rule Builder RedKit · Infrastructure Scanner
Support
Troubleshooting Get in touch Become a Partner
MCP Integration
Connect Claude and other AI assistants to mlab.sh through the Model Context Protocol server.
Copy MarkdownOpen
mlab.sh exposes a Model Context Protocol (MCP) server that lets Claude and other AI assistants query threat intelligence, run scans, and manage your account directly from a conversation.
Official support: Claude only. This MCP integration has been tested and is officially supported on Claude (claude.ai web and Claude Desktop). Other MCP-compatible clients may work but are neither tested nor guaranteed - use them at your own discretion and expect no dedicated support for third-party clients.
Endpoint and transports
The MCP server is available at a single URL and supports two transports:
- Streamable HTTP -
POST https://mlab.sh/mcp - SSE -
GET https://mlab.sh/mcp
Authentication: All requests require a Bearer token in the Authorization header. Tokens start with mcp_ and can be created in Account → Settings → MCP Tokens or via OAuth from any compatible AI client (e.g. Claude.ai).
Claude.ai web connector (recommended)
Claude.ai supports remote MCP connectors via OAuth 2.0. No token to copy - authorization is handled automatically.
Open Claude.ai → Settings → Integrations → Add connector (or the connector icon in the chat input bar).
Enter the MCP server URL:
https://mlab.sh/mcp
Claude.ai will redirect you to mlab.sh to authorize the connection. Click Authorize - done.
Claude Desktop (local)
Claude Desktop uses a stdio bridge (mcp-remote) to connect to remote HTTP servers. Requires Node.js.
Create an MCP token in Account → Settings → MCP Tokens.
Open your Claude Desktop config file:
# macOS
~/Library/Application Support/Claude/claude_desktop_config.json
# Windows
%APPDATA%\Claude\claude_desktop_config.json
Add the following entry (replace mcp_xxx with your token):
{
"mcpServers": {
"mlab": {
"command": "npx",
"args": [
"-y",
"mcp-remote",
"https://mlab.sh/mcp",
"--header",
"Authorization: Bearer mcp_xxx"
]
}
}
}
Restart Claude Desktop. The mlab tools will appear in the tool picker.
Available tools
| Tool | Description | Parameters |
|---|---|---|
detect_ioc | Auto-detect IOC type and enrich IPs with geolocation & reputation | value |
scan_ip | Look up an IPv4 or IPv6 address, or a CIDR range. Geolocation, ISP, ASN, network type, TOR status, reverse DNS with forward confirmation, and the RDAP allocation with its abuse contact | ip |
start_domain_scan | Launch a domain scan (returns cached results instantly if available) | domain |
get_domain_scan_results | Poll scan results - DNS, subdomains, SSL, security.txt, robots.txt | domain |
get_scan_history | Recent scan history, optionally filtered by type | type? limit? |
get_bookmarks | List saved bookmarks (IPs, domains, hashes) | limit? |
add_bookmark | Save an IOC to bookmarks | value |
remove_bookmark | Remove an IOC from bookmarks | value |
scan_crypto | Look up a blockchain address - labels, sanctions, risk score. 18 chains, all reachable. Pass chain for an EVM address: it cannot be derived, and a wrong guess loses every label | address chain? |
cve_search | Search CVEs by keyword, product, vendor or CVE ID. Returns CVSS score, severity, EPSS probability, KEV status and affected products | query severity? date_start? date_end? limit? page? |
cve_detail | Full record for a single CVE - CVSS vector breakdown, CWE weaknesses, references, EPSS exploitation probability and CISA KEV dates | cve_id |
search_actors | Search threat actors by name or alias - optional filters on origin, incident type and targeted sector. MISP Galaxy data only | query origin? motivation? sector? limit? |
get_actor | Profile of a threat actor from MISP Galaxy (description, origin, state sponsor, synonyms, targeted countries & sectors, references) plus its MITRE ATT&CK tools and techniques. Keep the sources block when quoting | slug |
get_scan_limits | Remaining daily quotas for IP, domain, file and crypto scans | - |
get_account_info | Current user, organization and subscription plan | - |
Token management
MCP tokens are personal and scoped to your user account: they act as you, with your organization role, and are not affected by API key permissions, which apply to organization API keys only. You can create up to 5 active tokens, or 100 on the Team and Enterprise plans. Tokens can be revoked at any time from Account → Settings.
Tokens issued via OAuth (e.g. from Claude.ai) are also listed there, labeled OAuth: <client name>.
Overview Ways to plug mlab.sh into your stack - AI assistants, automation platforms, CI/CD, your editor and your browser. n8n Integration Automate mlab.sh scanning, CVE intelligence and threat-actor data from your n8n workflows with the official community node package.
On this page
Endpoint and transports Claude.ai web connector (recommended) Claude Desktop (local) Available tools Token management
[{"@context":"https://schema.org","@type":"Organization","name":"mlab","url":"https://mlab.sh","logo":"https://doc.mlab.sh/logo.png"},{"@context":"https://schema.org","@type":"WebSite","name":"mlab documentation","url":"https://doc.mlab.sh","description":"Documentation for the entire mlab stack - core platform, API, dashboard, CLI, SDKs and infrastructure."}]
