ir.mlab.sh · v1.0.0

Your alerts deserve
a real workflow.

A self-hosted incident response platform that turns security alerts into structured investigations: enriched by nine intelligence sources, escalated into incidents with a regulatory clock, and closed with a report. Entirely on your own infrastructure.

100%
Self-hosted
<5 min
Deploy time
Docker
One command
48h
Grace period
0€
Free tier

From alert to resolution

ir.mlab.sh structures the full incident response lifecycle into five clear stages.

Ingest

One endpoint that reads your SIEM's own field names, deduplicates on a key you choose, and classifies the observables in the payload.

Triage

Every alert arrives with its merged enrichment verdict. Decide explicitly: true positive, false positive, benign, or escalate.

Investigate

Cases with tasks, an append-only timeline, hashed evidence and correlation against every past investigation.

Respond

An incident with a commander, the five NIST phases, and the DORA, NIS2 or RGPD notification clock started automatically.

Close & review

A printable dossier, a post-incident review scored per phase, and action items carrying a due date and a change reference.

Everything your SOC needs

Built by security professionals, for security professionals. No bloat, no noise - just the tools that matter.

Alert ingestion

One endpoint takes an alert from a SIEM, an EDR or a script. The sender keeps its own field names.

  • Splunk, Elastic and Sentinel field mapping
  • Deduplication on a key you control
  • 1 000 alerts a minute, batches of 200
Cases and incidents

A case is one investigation. An incident is what the organisation has to answer for, with its own lifecycle.

  • Tasks, templates, notes, custom fields
  • Incident commander and NIST phases
  • SLA deadlines that recompute on escalation
Enrichment catalog

Nine sources asked at once, merged into one verdict, cached for six hours per organisation.

  • VirusTotal, AbuseIPDB, GreyNoise, MISP and more
  • Routing per observable type
  • Declare your own REST source, no rebuild
Regulatory compliance

Assign a framework and every notification it requires appears with its deadline already calculated.

  • DORA Art. 19, NIS2 Art. 23, RGPD Art. 33
  • ICT incident and RGPD violation registers
  • Post-incident reviews with action items
Automation

A visual DAG editor for the mechanical work, and webhooks for everything downstream.

  • HTTP, condition, transform and delay nodes
  • Slack, Discord, Teams or a signed endpoint
  • Per-node execution history
Access control

Twelve permission bits per member, checked on every route, plus optional TLP enforcement.

  • TOTP and WebAuthn passkeys
  • Account keys and app tokens, scoped apart
  • Append-only audit trail in ClickHouse

Self-hosted, private, yours

Your data never leaves your infrastructure. Deploy with Docker Compose in under 5 minutes. No SaaS dependency, no vendor lock-in.

Docker Compose

Single docker compose up to deploy the full stack. App, executor, MySQL & ClickHouse included.

Minimal requirements

2 GB RAM, 10 GB disk. Runs on any Linux server, VPS or local machine.

Auto-migrations

Database schema updates run automatically on startup. Just pull and restart.

48h grace period

License checks every hour via HMAC. If your server goes offline, ir.mlab.sh keeps running for 48 hours.

No hidden features behind paywalls

Self-hosted deployment

Run on your own infrastructure. Your data stays with you.

Granular permissions

Twelve permission bits per member, checked on every route, plus optional TLP enforcement.

Complete audit timeline

Append-only in ClickHouse, two-year default retention, configurable from 30 to 3 650 days.

REST API and webhooks

Every entity over a documented API, plus outbound webhooks to Slack, Discord, Teams or your own endpoint.

Free upgrades

Every release includes new features and fixes at no extra cost.

48-hour license resilience

Grace period ensures continuity if license server is temporarily unreachable.

Automatic database migrations

Schema updates apply on startup. No manual SQL needed.

Two-factor authentication

TOTP and WebAuthn passkeys on every tier, with an option to force enrolment workspace-wide.

Stop using spreadsheets for incidents

Most teams still manage incidents with shared docs, Slack threads and email chains. ir.mlab.sh gives you a proper platform without the enterprise price tag.

Spreadsheets
& Emails
Enterprise
SOAR
Open-source
IR tools
ir.mlab.sh
Self-hosted
Deploy in <5 min
Case management
Alert triage workflow
Observable correlation
REST API
Multi-source enrichment
DORA / NIS2 / RGPD deadlines
Visual playbooks
Enterprise SSO
Free tier available
Professional support
No vendor lock-in

Who is it for?

SOC Analysts

Triage alerts faster, investigate with context, and stop drowning in false positives.

Incident Responders

Coordinate response across teams with structured cases, evidence and timelines.

Blue Teams

Build detection context, track indicators, and feed findings back into your defenses.

CISOs & Managers

Get visibility into your team's workload, response times and investigation outcomes.

Ready to fix your incident workflow?

Deploy ir.mlab.sh in under 5 minutes. Free tier included, no credit card required.