ThreatBook
ThreatBook is a Beijing-based cybersecurity company, founded in 2015, that provides AI-powered threat intelligence, NDR, DNS security, and digital risk protection to enterprise SOCs globally, with a distinctive focus on firsthand APAC adversary data.
- Company typePrivate
- Founded2015
- HeadquartersBeijing, China
- Headcount501–1,000
- GTM typeB2B
- OfferingSoftware
What ThreatBook does
ThreatBook is a Beijing-headquartered cybersecurity company founded in 2015 that builds an AI-powered threat intelligence and detection platform targeted at enterprise security operations centers. The company's core technology is a firsthand APAC threat intelligence stack — ThreatBook ATI — that analyzes more than 14 billion cyber-attack records daily, identifies 80M+ malicious IPs, and maintains adversary profiles on 200+ APT groups and 1,000+ cybercrime groups, with AI-based filtering combined with human analyst cross-verification. This intelligence spine powers an integrated product portfolio: ThreatBook TDP (a full-traffic NDR platform claiming <0.03% false positive rate), OneDNS (DNS-layer threat blocking), DRPS (digital risk protection), ThreatBook Investigator (analyst-facing investigation tool), and the recently launched Flocks (open-source agentic SOC platform coordinating seven specialist agents across 150+ integrations) and SafeSkill (AI agent skill vetting).
The company operates a B2B enterprise SaaS model with annual or multi-year subscriptions sold through a direct field-sales motion targeting CISOs and security decision-makers, supplemented by self-service portals for community and developer-led adoption of open-source and freemium products. Customers include a mix of global multinationals (Starbucks, BMW, BlackRock, KPMG, Airbnb, Honda, Lululemon, Estée Lauder) and large Chinese internet and financial firms (Tencent, JD.com, ByteDance, Ant Group), spanning automotive, financial services, retail, hospitality, FMCG, and technology. ThreatBook has accumulated more than $200M in disclosed venture funding across eight rounds through a 2022 Series E+ led by CDH Investment, operates regional hubs in Singapore, Hong Kong, Abu Dhabi, and Riyadh alongside its Beijing headquarters, and holds third-party validation through Gartner Magic Quadrant 2025 placement for NDR and three consecutive years as a Strong Performer in Gartner Peer Insights Voice of the Customer for NDR.
ThreatBook firmographics
Firmographics- Name
- ThreatBook
- Legal name
- ThreatBook
- Website
- https://threatbook.com
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 501–1,000 employees
- Short description
- ThreatBook is a Beijing-based cybersecurity company, founded in 2015, that provides AI-powered threat intelligence, NDR, DNS security, and digital risk protection to enterprise SOCs globally, with a distinctive focus on firsthand APAC adversary data.
- Ownership category
- akta.pro rank
ThreatBook industry classification
Industry- Product category
- Cybersecurity — Threat Intelligence and Network Detection and Response
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Threat Intelligence Services (BPAEADAC)
- akta.pro secondary industries
- Security Awareness & Phishing Simulation (Email/Collab-focused) (HDADAKAJ), Prompt Security & Injection Defense (HDAAAKAE), Insider Threat Program Design & Risk Assessments (BPAKADAM), Email & Collaboration Threat Detection/Response (ICR/CTDR) (HDADAKAI)
Keywords
Where ThreatBook is headquartered
LocationHeadquarters
- HQ city
- Beijing
- HQ country
- China
- HQ region
- Asia
Offices5 records
Markets served
ThreatBook business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure
Revenue model
- Enterprise SaaS Subscriptions (TDP, ATI, OneDNS, DRPS): ThreatBook generates revenue primarily through subscription-based licensing of its commercial products including Threat Detection Platform (TDP), Advanced Threat Intelligence (ATI), OneDNS, and DRPS. These are sold to enterprise security teams on annual or multi-year subscription terms, typical of B2B SaaS security products.
- SafeSkill - AI Agent Security: SafeSkill, the AI agent security product launched as part of ThreatBook's rebrand, is available through a web portal and likely follows a subscription or tiered licensing model for enterprise deployment of AI skills verification.
- Open-Source Platform (Flocks): Flocks is positioned as an open-source, locally deployed agentic SOC platform available via GitHub. While open-source at its core, it may drive demand for ThreatBook's commercial enterprise products and professional services.
Go-to-market motion3 records
Distribution channels4 records
Marketing channels8 records
ThreatBook product offering
Product offeringCore offering
ThreatBook sells an integrated AI-powered cybersecurity platform anchored on firsthand APAC threat intelligence produced since 2015. Its commercial offerings include Advanced Threat Intelligence (ATI), a Threat Detection Platform (TDP) for network detection and response, OneDNS for DNS-layer threat blocking, Digital Risk Protection (DRPS), Flocks (an open-source agentic SOC platform coordinating seven specialist agents across 150+ tools), and SafeSkill (an AI agent security product that inspects MCPs, plugins, and AI skills before enterprise deployment). All products draw from a shared intelligence base analyzing 14 billion cyber-attack records daily and tracking 200+ APT groups and 1,000+ cybercrime groups across Asia Pacific.
Product overview
ThreatBook is The Agentic Security Company offering an integrated security operations platform combining six products across three categories. The core threat intelligence stack includes: ThreatBook ATI (Advanced Threat Intelligence) as the intelligence spine analyzing 14B+ attack records daily; ThreatBook TDP (Threat Detection Platform) for full-traffic NDR with <0.03% false positive rate; ThreatBook OneDNS for DNS-layer threat blocking; and ThreatBook DRPS for digital risk protection. The AI-for-Security category includes Flocks, an open-source agentic SOC platform coordinating 7 specialist agents across 150+ integrations for autonomous SecOps. The Security-for-AI category includes SafeSkill for vetting AI agent skills and MCP/plugins before deployment. All products draw from firsthand APAC threat intelligence that the company has tracked since 2015.
Differentiator
Problem solved
Functional benefit
Brands
- ThreatBook ATI: Advanced Threat Intelligence solution that serves as the intelligence spine powering every product in the stack with firsthand APAC adversary data.
- ThreatBook TDP
- DRPS
- OneDNS
- Flocks
- SafeSkill
- ThreatBook Investigator
Products and services
- ThreatBook ATI (Advanced Threat Intelligence) Advanced Threat Intelligence platform serving as the intelligence spine for the entire ThreatBook product stack. Analyzes 14 billion cyber-attack records daily, identifies 80M+ malicious IPs, and tracks 200+ APT groups and 1,000+ cybercrime groups across Asia Pacific. Delivers threat intelligence through AI-based filtering combined with human analyst cross-verification to achieve 99.99% accuracy and low false positive rates. For enterprise security teams and SOC operators.
- ThreatBook TDP (Threat Detection Platform) Full-traffic Network Detection and Response (NDR) platform achieving less than 0.03% false positive rate and 85x alert noise reduction through multi-dimensional IP reputation analysis. Recognized in the 2025 Gartner Magic Quadrant for NDR and awarded Strong Performer in Gartner Peer Insights Voice of the Customer for NDR for three consecutive years. For enterprise SOC teams needing high-accuracy network threat detection.
- ThreatBook OneDNS Secure Enterprise DNS service that blocks threats at the DNS layer before they reach endpoints, powered by live ATI feeds for real-time threat blocking. For enterprise IT and security teams needing DNS-layer defense.
- ThreatBook DRPS (Digital Risk Protection) Digital Risk Protection service that monitors external attack surface and brand exposure, covering dark web, domain squatting, and other digital risk vectors, integrated with the broader ThreatBook intelligence stack. For enterprise security, brand protection, and fraud teams.
- Flocks Open-source, locally deployed agentic SOC platform distributed via GitHub. Coordinates seven specialist agents across 150+ integrated security tools to autonomously run triage, correlation, and response inside existing enterprise infrastructure. For SOC teams seeking AI-native security operations automation.
- ThreatBook SafeSkill AI Agent Security product that scans every MCP, plugin, and AI skill before it touches the enterprise environment. Inspects and evaluates AI agent skills to detect tampering or hidden risks, offering 10,000+ verified skills. Distributed via standalone portal at safeskill.io. For enterprises deploying AI agents, plugins, and AI skills at scale.
- ThreatBook Investigator Threat investigation platform accessible via self-service portal at i.threatbook.io for security analysts to query threat intelligence and conduct investigations.
Quantifiable outcome
- 99.99% Threat Intelligence Accuracy (ATI)
- +8 more outcomes
Companies that use ThreatBook
Customer profileNamed customers14 records
Segments10 records
Ideal customer profiles3 records
ThreatBook technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability7 records
Feature7 records
ThreatBook partnerships and signals
Strategic signalScale indicators16 records
Recent moves6 records
Expansion highlights6 records
ThreatBook competitors and assessment
Company assessmentDirect peers
- Recorded Future: Recorded Future is a direct competitor in the threat intelligence space, offering intelligence feeds, APT tracking, and integrated security analytics. Both companies sell intelligence-driven security platforms to enterprise SOCs, though Recorded Future is owned by Mastercard and serves a more Western customer base.
- Mandiant (Google Cloud): Mandiant is a leading threat intelligence and incident response firm, now part of Google Cloud. It overlaps directly with ThreatBook ATI on APT group tracking, adversary profiles, and intelligence delivery to enterprise security teams, and serves as a benchmark for the threat intelligence category.
- QiAnXin Technology: QiAnXin is one of the largest Chinese cybersecurity companies, offering threat intelligence, endpoint security, and SOC platforms. It is ThreatBook's most direct domestic competitor, competing for the same Chinese enterprise and government customers in threat intelligence and NDR.
- Venustech Group: Venustech is a major Chinese cybersecurity vendor offering threat intelligence, firewall, IDS/IPS, and managed security services. It competes with ThreatBook across multiple product lines within the Chinese enterprise and government market.
- Anomali: Anomali is a threat intelligence platform provider offering intelligence feeds, TIP functionality, and integrated detection products. It directly competes with ThreatBook ATI and ThreatBook Investigator in the threat intelligence management category for enterprise SOCs.
Broad incumbents
- CrowdStrike: CrowdStrike is a broad incumbent in endpoint and extended detection and response (EDR/XDR/NDR) and threat intelligence through Charlotte AI and Falcon Intelligence. While CrowdStrike's core is endpoint, it competes with ThreatBook TDP in NDR and adjacent intelligence use cases for global enterprise buyers.
- SentinelOne: SentinelOne is a major AI-driven endpoint security and XDR platform with growing threat intelligence capabilities. It is a broader incumbent competing in adjacent categories to ThreatBook's TDP and increasingly in the agentic SOC space that Flocks targets.
- Palo Alto Networks (Unit 42): Palo Alto Networks is a broad cybersecurity incumbent with threat intelligence (Unit 42), NDR (Cortex XDR), and AI security capabilities. It competes with ThreatBook across threat intelligence, NDR, and increasingly in the AI security category that SafeSkill addresses.
Emerging players
- Darktrace: Darktrace applies AI/ML to network detection, threat identification, and autonomous response. It overlaps with ThreatBook TDP in NDR and with Flocks in the agentic/autonomous SOC concept, though Darktrace's approach is more anomaly-detection-led and serves a global Western enterprise base.
- Tines: Tines is a security orchestration, automation, and response (SOAR) platform that overlaps with Flocks' integration and automation capabilities. Both products focus on streamlining SOC workflows and reducing manual analyst effort, though Tines is workflow-orchestration focused while Flocks adds autonomous agentic capabilities.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
ThreatBook social profiles
Digital presenceThreatBook financial estimates
Financial estimateRevenue estimate
Valuation estimate
ThreatBook leadership team
Management profileNumber of profiles
Profiles1 record
ThreatBook funding detail
Funding detailFunding overview
Funding rounds8 records
Investors13 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ThreatBook M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ThreatBook
What does ThreatBook do?
ThreatBook sells an integrated AI-powered cybersecurity platform anchored on firsthand APAC threat intelligence produced since 2015. Its commercial offerings include Advanced Threat Intelligence (ATI), a Threat Detection Platform (TDP) for network detection and response, OneDNS for DNS-layer threat blocking, Digital Risk Protection (DRPS), Flocks (an open-source agentic SOC platform coordinating seven specialist agents across 150+ tools), and SafeSkill (an AI agent security product that inspects MCPs, plugins, and AI skills before enterprise deployment). All products draw from a shared intelligence base analyzing 14 billion cyber-attack records daily and tracking 200+ APT groups and 1,000+ cybercrime groups across Asia Pacific.
Is ThreatBook a public or private company?
ThreatBook is a private company. It is classified as venture growth investor backed and is currently operating.
When was ThreatBook founded?
ThreatBook was founded in 2015. It employs 501 to 1,000 people.
Where is ThreatBook based?
ThreatBook is headquartered in Beijing, China, in the Asia region.
How does ThreatBook make money?
Three revenue lines are on record. Enterprise SaaS Subscriptions (TDP, ATI, OneDNS, DRPS) is the primary driver. The others are safeSkill - AI Agent Security and open-Source Platform (Flocks).
Who are ThreatBook's main competitors?
Direct peers on record are Recorded Future, Mandiant (Google Cloud), QiAnXin Technology, Venustech Group and Anomali. Broad incumbents are CrowdStrike, SentinelOne and Palo Alto Networks (Unit 42). Emerging players are Darktrace and Tines.
Does ThreatBook have an API?
No public API is recorded for ThreatBook.
What industry is ThreatBook in?
ThreatBook's product category is Cybersecurity — Threat Intelligence and Network Detection and Response. Its primary akta.pro industry code is BPAEADAC, Threat Intelligence Services, with a secondary code of HDADAKAJ, Security Awareness & Phishing Simulation (Email/Collab-focused). Its NAICS code is 5415 and its SIC code is 7373.