ir.mlab.sh · v1.0.0 · self-hosted

Your alerts deserve a real workflow.

A self-hosted incident response platform that turns scattered security alerts into structured investigations, enriched by nine intelligence sources and closed with the regulatory notification already filed. All on your own infrastructure.

Self-hosted · your data never leaves your infrastructure · latest release →
POST /api/v1/ingest/alert
Splunk CrowdStrike SentinelOne Elastic Wazuh Sentinel Defender Proofpoint Anything with a webhook
mlab.sh VirusTotal AbuseIPDB GreyNoise urlscan.io AlienVault OTX Shodan MISP Have I Been Pwned

From alert to resolution

Five clear stages, one consistent platform. See it in detail →

Ingest

One endpoint. Your SIEM's field names, not ours. Deduplicated on a key you choose.

Triage

Every alert arrives with its enrichment verdict. Decide, then escalate or close with a reason.

Investigate

Cases with tasks, timeline, hashed evidence and correlation across every past investigation.

Respond

Incident commander, NIST phases, and the DORA, NIS2 or RGPD clock started automatically.

Close & review

A PDF dossier, a scored post-incident review, and action items with a due date.

A queue that doesn't lie

Every alert in one place, severity-coded, SLA-aware. New incidents flash in real-time as your sources fire.

  ir.example.com / dashboard
Triage queue · 42 open alerts
live
Suspicious PowerShell on WS-042 crowdstrike 2 obs. 14:02
Beaconing to known C2 - 203.0.113.4 splunk 5 obs. 14:01
Unusual login geo - user alice@ azure-ad 3 obs. 13:58
Brute-force attempts on SSH bastion wazuh 1 obs. 13:54
EDR sensor offline - WS-117 sentinel-one - 13:42
Phishing - HR impersonation campaign proofpoint 8 obs. 13:31

Made for the people on call

Whatever your seat at the table, mlab IR gives you what you actually need at that seat.

Persona / SOC analyst

Stop drowning in false positives.

"My queue is 400 deep before lunch. Half is noise I've already seen this month."

Deduplication on a key your detection rule owns, nine enrichment sources answering before you open the alert, and a triage decision that is recorded rather than implied.

Persona / IR lead

Coordinate without losing thread.

"During an incident we're across three Slack channels, two Google Docs and a war-room call. Hand-off kills us."

One incident with a named commander, a responder team, a shared timeline, and webhooks pushing every state change into the channel the team already watches. The report writes itself at closure.

Persona / CISO

Numbers I can show the board.

"I need MTTD, MTTR, top noisy sources, and proof we notified the regulator in time. Today I rebuild this every quarter."

Live dashboards, an append-only audit trail, and the DORA ICT incident register as a one-click export. The platform does the bookkeeping.

Coverage you can defend in a meeting

Tag cases with techniques. mlab IR builds a heat-map across the matrix - every cell tells you how many cases hit it, and when.

Coverage Saturated

One indicator, nine opinions, one verdict

An observable arrives as a value and nothing else. Every source you enable is asked at once, and the answers merge into a single verdict with each source still readable underneath. See the catalog →

Nine sources in the box

mlab.sh, VirusTotal, AbuseIPDB, GreyNoise, urlscan.io, AlienVault OTX, Shodan, MISP and Have I Been Pwned. Most have a usable free tier.

Routed by type

A grid decides who answers for addresses, domains, hashes and the rest, with on demand and automatic as separate switches so a rate-limited key stays useful.

Or your own source

Any REST API returning JSON: a URL template, an auth header and a few JSON paths. No code, no rebuild, no waiting for us.

The clock starts when the incident does

Assign a framework to an incident and every notification it requires is created with its deadline already calculated. DORA, NIS2, RGPD and ISO 27001 in detail →

Deadlines, not reminders

DORA Art. 19 at 4h, 72h and 30 days. NIS2 Art. 23 at 24h, to the authority and the CSIRT. RGPD Art. 33 at 72h. Overdue ones surface on the dashboard.

Registers you can export

The DORA ICT incident register and the RGPD violations register, as JSON or CSV, with classification, costs and notification history intact.

Reviews that close the loop

Hot reviews at five days, cold at 180, each NIST phase scored, and action items carrying the change request that implemented them.

SOAR features, without the SOAR price tag

Enterprise SOAR vendors charge six figures. Spreadsheets cost zero but lose every thread. mlab IR sits between - a proper platform you actually own.

Your infrastructure, your data

Runs entirely on your servers. The only call that is always on is an hourly license HMAC. Every byte that can leave, listed →

5 minutes to running

docker compose up and you're done. No agents, no ETL, no consulting hours to book.

No vendor lock-in

REST API for everything. MySQL and ClickHouse under the hood. Export your data any time, no exit fee.

How we compare

Spreadsheets
& Slack
Enterprise
SOAR
Open-source
IR tool
mlab IR
Self-hosted
Deploy in < 5 min
Structured workflow
MITRE ATT&CK
Cross-case correlation
Multi-source enrichment
DORA / NIS2 / RGPD deadlines
Visual playbooks
Enterprise SSO
Free tier
Professional support
No vendor lock-in
0
min to deploy
0
offline grace period
0
self-hosted
0
to start
"Most teams don't lack tools. They lack a place where the alert, the case, the evidence and the verdict all live together. That's the whole product."
The mlab team / Cyber Dream

Common questions

No. The only call that is always on is an hourly license validation HMAC, carrying the tier, a timestamp and a nonce. No alert, case, observable or evidence ever leaves your infrastructure. Enrichment lookups and webhooks only reach destinations you configured yourself. The full egress list is here.
For up to 48 hours at a time, which is the grace window. Beyond that the instance locks until you restore outbound HTTPS to mlab.sh. Talk to us about air-gapped deployments on the Corporate tier.
Same self-hosted spirit, plus an incident layer with regulatory deadlines, a nine-source enrichment catalog and built-in metrics. Everything is exposed over the REST API, so importing existing cases is a script you write against a documented endpoint rather than a migration tool we ship.
3 users, 10 alerts a month, 5 cases and 50 observables. Designed for solo analysts and evaluations. The whole platform is there, only the monthly caps differ, and upgrading is a licence change with no reinstall.
Yes. Drop the database containers from compose, point DB_HOST and CH_HOST at your managed instances. App and executor stay stateless.
If your "SOAR" was being used as a case management tool, no. mlab IR has a visual playbook editor with HTTP, condition, transform and delay nodes for the mechanical work. If you need orchestration across dozens of vendor integrations, run both: everything here is exposed over webhooks and REST.
Not in this build, and we would rather say so here than during your evaluation. Authentication is a password plus a second factor, TOTP or a WebAuthn passkey, with server-side sessions and REQUIRE_2FA to force enrolment across a workspace.
There is no STIX or TAXII export in this build. Observables leave as CSV, JSON, JSONL or Markdown, or through the REST API. MISP is supported as an enrichment source, meaning ir queries your instance, not the other way round.

Ready to fix your incident workflow?

Free tier included. No credit card. Up and running in under 5 minutes.