Triage any indicator of compromise (IOC) through mlab.sh - IPs, CIDR ranges, domains, URLs, file hashes, email addresses, MAC addresses, phone numbers or blockchain addresses. Detects the indicator type, runs the right lookups, pivots to malware families, threat actors and CVEs, and produces an analyst-ready verdict. Use when the user pastes one or more indicators, or asks to check, triage, enrich, or investigate an IOC.