mlab.sh is answering right now. Last checked 2 min ago. Last commit 31 Aug 2026.
Threat intelligence: enrich IOCs (IP, domain, URL, hash), search CVEs and actors, scan SBOMs.
Today is the operative word: we check mlab.sh every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 2 min ago.
claude mcp add mcp --transport http https://mlab.sh/mcp
{
"mcpServers": {
"mcp": {
"url": "https://mlab.sh/mcp"
}
}
}
[mcp_servers.mcp]
url = "https://mlab.sh/mcp"
{
"mcpServers": {
"mcp": {
"url": "https://mlab.sh/mcp"
}
}
}
{
"mcpServers": {
"mcp": {
"url": "https://mlab.sh/mcp"
}
}
}
This endpoint answered with an authorization challenge — the server is running, but you need an API key or OAuth to use it.
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://mlab.sh/mcp | sse | needs key | 317 ms | 2 min ago |
Domain/IP intelligence, web page capture and search APIs
Threadlinqs threat-intelligence MCP — 49 tools: threats, detections, IOCs, actors, C2, MITRE, CVEs
Threadlinqs threat-intelligence MCP — 73 tools: threats, detections, IOCs, actors, C2, MITRE, CVEs
Enrich, search, assess, and manage threat intelligence through 80+ typed MCP tools.
Pulsedive MCP — threat-intelligence IOC enrichment (pulsedive.com)
VulnCheck exploit intelligence — CVE research, exploit data, advisories, and threat analysis.
Breach intelligence API: email search, domain monitoring, passwords and stealer logs.
European hosting & domain market intelligence: M&A tracking, operator dossiers, screening.
Answers built from our own checks of this server.