Your alerts deserve a real workflow.
A self-hosted incident response platform that turns scattered security alerts into structured investigations, enriched by nine intelligence sources and closed with the regulatory notification already filed. All on your own infrastructure.
Ingest
One endpoint. Your SIEM's field names, not ours. Deduplicated on a key you choose.
Triage
Every alert arrives with its enrichment verdict. Decide, then escalate or close with a reason.
Investigate
Cases with tasks, timeline, hashed evidence and correlation across every past investigation.
Respond
Incident commander, NIST phases, and the DORA, NIS2 or RGPD clock started automatically.
Close & review
A PDF dossier, a scored post-incident review, and action items with a due date.
A queue that doesn't lie
Every alert in one place, severity-coded, SLA-aware. New incidents flash in real-time as your sources fire.
Triage queue · 42 open alerts
liveMade for the people on call
Whatever your seat at the table, mlab IR gives you what you actually need at that seat.
Stop drowning in false positives.
Deduplication on a key your detection rule owns, nine enrichment sources answering before you open the alert, and a triage decision that is recorded rather than implied.
Coordinate without losing thread.
One incident with a named commander, a responder team, a shared timeline, and webhooks pushing every state change into the channel the team already watches. The report writes itself at closure.
Numbers I can show the board.
Live dashboards, an append-only audit trail, and the DORA ICT incident register as a one-click export. The platform does the bookkeeping.
Coverage you can defend in a meeting
Tag cases with techniques. mlab IR builds a heat-map across the matrix - every cell tells you how many cases hit it, and when.
One indicator, nine opinions, one verdict
An observable arrives as a value and nothing else. Every source you enable is asked at once, and the answers merge into a single verdict with each source still readable underneath. See the catalog →
Nine sources in the box
mlab.sh, VirusTotal, AbuseIPDB, GreyNoise, urlscan.io, AlienVault OTX, Shodan, MISP and Have I Been Pwned. Most have a usable free tier.
Routed by type
A grid decides who answers for addresses, domains, hashes and the rest, with on demand and automatic as separate switches so a rate-limited key stays useful.
Or your own source
Any REST API returning JSON: a URL template, an auth header and a few JSON paths. No code, no rebuild, no waiting for us.
The clock starts when the incident does
Assign a framework to an incident and every notification it requires is created with its deadline already calculated. DORA, NIS2, RGPD and ISO 27001 in detail →
Deadlines, not reminders
DORA Art. 19 at 4h, 72h and 30 days. NIS2 Art. 23 at 24h, to the authority and the CSIRT. RGPD Art. 33 at 72h. Overdue ones surface on the dashboard.
Registers you can export
The DORA ICT incident register and the RGPD violations register, as JSON or CSV, with classification, costs and notification history intact.
Reviews that close the loop
Hot reviews at five days, cold at 180, each NIST phase scored, and action items carrying the change request that implemented them.
SOAR features, without the SOAR price tag
Enterprise SOAR vendors charge six figures. Spreadsheets cost zero but lose every thread. mlab IR sits between - a proper platform you actually own.
Your infrastructure, your data
Runs entirely on your servers. The only call that is always on is an hourly license HMAC. Every byte that can leave, listed →
5 minutes to running
docker compose up and you're done. No agents, no ETL, no consulting hours to book.
No vendor lock-in
REST API for everything. MySQL and ClickHouse under the hood. Export your data any time, no exit fee.
How we compare
| Spreadsheets & Slack |
Enterprise SOAR |
Open-source IR tool |
mlab IR | |
|---|---|---|---|---|
| Self-hosted | ||||
| Deploy in < 5 min | ||||
| Structured workflow | ||||
| MITRE ATT&CK | ||||
| Cross-case correlation | ||||
| Multi-source enrichment | ||||
| DORA / NIS2 / RGPD deadlines | ||||
| Visual playbooks | ||||
| Enterprise SSO | ||||
| Free tier | ||||
| Professional support | ||||
| No vendor lock-in |
"Most teams don't lack tools. They lack a place where the alert, the case, the evidence and the verdict all live together. That's the whole product."
Common questions
DB_HOST and CH_HOST at your managed instances. App and executor stay stateless.REQUIRE_2FA to force enrolment across a workspace.Ready to fix your incident workflow?
Free tier included. No credit card. Up and running in under 5 minutes.