Skip to content

feat: add mlab.sh app - #456

Open
Sn0wAlice wants to merge 1 commit into
Shuffle:masterfrom
Sn0wAlice:add-mlab-app
Open

Sn0wAlice wants to merge 1 commit into
Shuffle:masterfrom
Sn0wAlice:add-mlab-app

Conversation

@Sn0wAlice

Copy link
Copy Markdown

mlab.sh app (mlab/1.0.0)

Adds a Python app for mlab.sh: threat intelligence and scanning for SOC workflows.

25 actions:

  • Scanning: domain (full scan with optional wait, status, results, SSL, network requests), IP, crypto address (single + bulk), hash (single + bulk), file upload + results, URL, email, phone, MAC
  • IOC extraction: pull indicators out of raw text, with optional SMS threat scoring
  • CVE intelligence: search, detail (EPSS / KEV), latest
  • Threat actors: list / search, by slug, actors exploiting a given CVE
  • Quota: remaining daily quota per scan type

Auth: API key declared in the authentication block (apikey + optional url for self-hosted instances). CVE and threat-actor actions use the public mlab.sh APIs.

Implementation: shuffle_sdk.AppBase, frikky/shuffle:app_sdk base image, action names and parameters match api.yaml 1:1. Actions return the raw mlab.sh JSON, or {"success": false, "status", "error"} on HTTP errors. App README with the full action table is included.

Testing

Hotloaded on a local Shuffle instance (latest backend / orborus). All three workflows finished with every step at SUCCESS:

  • IP scan: lookup_ip → get_quota
  • Domain scan: scan_domain (wait for completion) → get_domain_ssl → get_quota
  • Threat context: get_cve → get_actors_by_cve (using $get_cve.id) → search_cves

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant