-
Notifications
You must be signed in to change notification settings - Fork 0
Home
The official command-line client for the mlab.sh threat-intelligence platform.
mlab talks to three hosts: the platform itself at mlab.sh, the CVE and
dependency scanner at vuln.mlab.sh, and the threat-actor database at
actors.mlab.sh. One binary, one config file at $HOME/.mlab/conf.yml, one
credential model — see Hosts for which command reaches which.
Everything renders for a terminal by default and as raw JSON on demand, so the same command serves an investigation and a pipeline.
| Command | What it does |
|---|---|
search |
Work out what you pasted and route it to the lookup that owns it. Start here. |
scan |
Launch a metered scan: a domain, an IP, a file, a crypto address. |
scan url … bash |
The cheap lookups: URL, hash, email, phone, MAC, shell script. |
status |
Where a running domain scan has got to. |
results |
Fetch a finished domain or file report. |
ssl |
The certificates a previous scan collected for a domain. |
ioc |
Pull indicators out of an email, a log or a report. |
network |
Every request a page makes, captured in an instrumented browser. |
cve |
Search, detail, export and dump the CVE catalogue. |
sbom scan |
Scan a lockfile and fail a CI build on what it finds. |
vuln query |
One package coordinate, OSV-compatible. |
actor |
Threat actors: list, detail, by-CVE, STIX, bulk export. |
limits |
What is left of each scan quota. |
login |
Store a key, check it, or forget it. |
open |
Jump to the matching web report. |
config |
Read and edit the config file and its profiles. |
completions, man |
Shell completions and a roff man page. |
- Hosts — three APIs with three different credential rules. Knowing which one a command uses explains most of its behaviour, including why some commands work with no key at all.
-
Authentication — the API key, the separate
vuln.mlab.shCI token, and the precedence between flag, environment and file. -
Configuration —
~/.mlab/conf.yml, profiles, and what the tool writes to disk. -
Output — the terminal render,
-o json,-o csvwhere it is honest, and the rules that keep progress out of a pipe. - Exit codes — the API reports quota, maintenance and bad input all as HTTP 400; the CLI turns that into a code you can branch on.
-
Releasing — how a version becomes a Homebrew formula, a
.deb, an.rpmand a set of tarballs.
brew tap mlab-sh/mlab-cli https://github.com/mlab-sh/mlab-cli
brew install mlab
mlab login
mlab whoamiThere are .deb and .rpm packages and tarballs for every target on the
releases page too. See
Install.
Nothing needs a credential to try: the CVE catalogue and the actor database are public.
mlab cve detail CVE-2024-3094
mlab actor get apt28The CLI is a client. It does not cache, it does not keep a local database, and
apart from the config file it writes nothing to disk that you did not redirect
there yourself. The one command that reaches a target rather than an API is
network, and even that runs server-side.