CTI League
- Company typePrivate
- Founded2020
- HeadquartersNew York, United States
- Headcount1,001–5,000
- GTM typeB2B
- OfferingServices
CTI League firmographics
Firmographics- Name
- CTI League
- Legal name
- CTI League
- Website
- https://cti-league.com
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 1,001–5,000 employees
- Ownership category
- akta.pro rank
CTI League industry classification
Industry- Product category
- Cybersecurity Threat Intelligence Services
- NAICS
- Investigation and Security Services (5616), Emergency and Other Relief Services (624230)
- SIC
- Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Threat Intelligence Services (BPAEADAC)
- akta.pro secondary industry
- Managed OT Security Services (MSSP/MDR for ICS/OT) (HDADAJAN)
Keywords
Where CTI League is headquartered
LocationHeadquarters
- HQ city
- New York
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
CTI League business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Infrastructure, Operations, Technology or R&D
Revenue model
- Pro-bono volunteer services: CTI League provides all services free of charge to the medical sector and life-saving organizations. The organization is volunteer-driven with no revenue generation. It is structured as a non-profit organization with services offered pro-bono. The organization explicitly states it is not a for-profit resource.
- No commercial revenue streams: CTI League is an all-volunteer non-profit group. No membership fees, product sales, or commercial services are offered. The organization does not market to anyone and does not share information with third parties for commercial purposes. Access to the platform is purely for threat intelligence work and not to be exploited as a for-profit resource.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free pro-bono services for medical sector and life-saving organizations |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels7 records
CTI League product offering
Product offeringCore offering
CTI League operates as the first Open Global Volunteer Emergency Response Center (CERT), delivering pro-bono cyber threat intelligence, vulnerability identification, incident response support, and lawful takedown of cybercriminal infrastructure to hospitals, the medical sector, and life-saving organizations (MS-LSO) worldwide. Its 1,500+ vetted volunteer members across 80+ countries collaborate via a private Slack workspace and security tool stack (Shodan, GreyNoise, VirusTotal) to neutralize cyber threats 24/7 across 22 timezones.
Product overview
CTI League is a volunteer-driven, non-profit organization that operates as the first Open Global Volunteer Emergency Response Center/CERT focused on protecting the medical sector and life-saving organizations (MS-LSO) worldwide from cyber-attacks. The organization offers four core service pillars: (1) Neutralization Service for takedowns, triage, and law enforcement escalations; (2) Prevention Service for vulnerability identification and IoC database creation; (3) Supporting Service for consultation and technical guidance; and (4) Health-Related Support for COVID-19 pandemic-related threats. The organization also publishes research reports including the Inaugural Report (March 2020) and CTIL Darknet Report 2021. CTI League members utilize platforms including Slack, Shodan, GreyNoise, and VirusTotal for threat intelligence work.
Differentiator
Problem solved
Functional benefit
Products and services
- CTI League Platform (Volunteer CERT) The first Open Global Volunteer Emergency Response Center (CERT), a trust-based, restricted-invite volunteer community connecting CTI experts, incident responders, and industry experts to provide pro-bono cyber threat intelligence and incident response services to hospitals, the medical sector, and life-saving organizations (MS-LSO) worldwide.
- Neutralization Service Cyberattack neutralization through lawful takedowns of threat actor assets and infrastructure, high-priority Indicator of Compromise (IoC) triage for medical sector networks, and law enforcement escalations to agencies and national CERTs.
- Prevention Service Prevention of cyber attacks against life-saving sectors through identifying vulnerabilities, compromised assets, and data leaks; creating databases of IoCs of threat actors; and reporting on trends and new Tactics, Techniques, and Procedures (TTPs).
- Supporting Service Consultation and technical support for the medical sector on cyber-protection capabilities, including domain and network profiling, infrastructure support, and guidance on mitigating cyber-attacks and data leaks. Includes cybersecurity incident investigation support covering the entire lifecycle of a cybersecurity incident.
- Health-Related Support Health-related cyber threat neutralization exploiting COVID-19 and other public safety events, providing a platform connecting experts from 22 timezones to coordinate protection of the medical sector and life-saving organizations.
- CTI League Inaugural Report (March 2020) First published report from CTI League, documenting the organization's founding on March 14, 2020 and achievements including 2,833 cybercriminal assets taken down and identification of 2,000+ vulnerabilities in healthcare institutions across 80+ countries.
- CTIL Darknet Report 2021 First Darknet Report from the CTIL-Dark team, cataloging criminal activity related to healthcare and the COVID pandemic, revealing top ransomware variants (Maze, Conti, Netwalker, Revil, Ryuk) affecting over 100 healthcare organizations, healthcare cybercrime victim distribution by region, and initial access broker activity targeting healthcare.
Quantifiable outcome
- 2,833 cybercriminal assets taken down, including 17 impersonating WHO, UN, and government organizations
- +4 more outcomes
Companies that use CTI League
Customer profileNamed customers3 records
Segments3 records
Ideal customer profiles2 records
CTI League technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
AI capability3 records
Feature4 records
CTI League partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered supporting and core.
- D3i (Cyber Intelligence Management Company)supportingD3i is a cyber intelligence management company acknowledged by CTI League for its special contribution to the platform. D3i enables intelligence teams to demonstrate their value through tested workflows and meaningful metrics, supporting CTI League's operational capabilities.
- SlackcoreCTI League uses Slack as its primary collaboration and communication platform. The organization operates a private, invite-only Slack workspace for vetted members to share threat intelligence, indicators of compromise, and coordinate responses across 22 timezones 24/7.
- ShodancoreCTI League utilizes Shodan as a core technology tool for scanning and identifying internet-connected devices and infrastructure, supporting vulnerability identification efforts targeting healthcare organizations worldwide.
- GreynoisecoreCTI League uses Greynoise for threat intelligence purposes, leveraging its internet-wide scanning data to identify and track threat actors targeting healthcare organizations and life-saving sectors.
- VirusTotalcoreCTI League uses VirusTotal as a core technology tool for analyzing and identifying malicious files, URLs, and indicators of compromise, supporting the organization's threat analysis and neutralization efforts.
- Law Enforcement Organizations (Global)coreCTI League works collaboratively with law enforcement organizations from all around the world. CTI League members support law enforcement in their fight against threats that are a danger for public safety, and law enforcement partners receive escalations from CTI League regarding relevant cyberattacks and malicious activity. The CTI League is the first community that enables law enforcement organizations from all around the world to work together with industry experts.
- US Cybersecurity and Infrastructure Security Agency (CISA)coreCISA released a public alert to the healthcare community on October 27, 2020 with technical indicators and attack patterns following a coordinated hospital attack. CTI League volunteers used CISA's data alongside their own sources to identify C2 infrastructure, track victims, and forecast future targets. CISA's partnership exemplifies government-industry collaboration in healthcare cybersecurity.
- National CERTs and Healthcare Ecosystem PartnerscoreCTI League escalates threats and vulnerabilities to national CERTs and works with healthcare ecosystem partners to alert potential victims. These partners include organizations within the healthcare sector that benefit from CTI League's threat intelligence and incident response capabilities. CTI League works directly with healthcare organizations, law enforcement, the intelligence community, and information sharing groups.
Scale indicators10 records
Recent moves6 records
Expansion highlights5 records
CTI League competitors and assessment
Company assessmentBroad incumbents
- Mandiant (Google Cloud): Commercial incident response and threat intelligence firm, now part of Google Cloud. Comparable in providing healthcare-targeted threat intelligence and incident response services, but as a paid commercial vendor with SLAs rather than volunteer pro-bono community.
- CrowdStrike: Commercial cybersecurity leader with a strong threat intelligence practice (Falcon Intelligence) covering adversary tactics and IoCs relevant to healthcare. Comparable as a competitor in healthcare threat intelligence, but operates as a large commercial vendor rather than volunteer non-profit.
Direct peers
- Cyber Threat Alliance: Non-profit organization of cybersecurity practitioners sharing threat intelligence to improve defenses. Comparable as a threat-intel sharing collective, though CTA is a paid-membership alliance of security vendors rather than volunteer-driven.
- Spamhaus Project: Volunteer-driven international non-profit that tracks spam, malware, and cyber threat infrastructure and shares data with law enforcement and network operators. Direct structural analog — small volunteer team, public-good mission, threat intelligence feeds, and CERT/law-enforcement coordination.
- Health-ISAC: Health Information Sharing and Analysis Center — a member-funded, healthcare-sector threat intelligence sharing community. Most directly comparable peer: serves the same customer base (hospitals, healthcare providers) with threat intel sharing, IoC exchange, and incident coordination, though it operates on a paid membership model rather than volunteer pro-bono.
- Global Cyber Alliance: Non-profit coalition dedicated to reducing cyber risk through cross-sector collaboration, including tools, resources, and intelligence sharing. Comparable as a mission-driven, multi-stakeholder non-profit tackling cyber threats at scale with a similar ethos of community-led defense.
- Shadowserver Foundation: Volunteer-driven, non-profit organization that collects and disseminates cyber threat intelligence globally. Comparable as a free, volunteer-operated threat intelligence entity that coordinates with law enforcement and national CERTs to neutralize malicious infrastructure — a close structural analog to CTI League's volunteer CERT model.
Regional players
- FS-ISAC: Financial Services Information Sharing and Analysis Center — analogous sector ISAC for financial services. Comparable structure (industry-specific threat intelligence sharing community serving critical infrastructure), but focused on financial sector rather than healthcare.
Emerging players
- No More Ransom Project: Public-private partnership initiated by law enforcement and cybersecurity organizations to help victims of ransomware retrieve encrypted data. Comparable mission overlap in ransomware response for critical sectors, though narrower in scope and partnership-driven rather than volunteer-driven.
- Have I Been Pwned: Free, public breach-notification service built and operated largely by a small team of security researchers. Comparable in operating as a community/public-good security resource without traditional commercial monetization, though narrower in scope (breach data) than CTI League's full-spectrum threat intel.
Market position
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
CTI League social profiles
Digital presenceCTI League financial estimates
Financial estimateRevenue estimate
Valuation estimate
CTI League leadership team
Management profileNumber of profiles
Profiles4 records
CTI League funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CTI League M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CTI League
What does CTI League do?
CTI League operates as the first Open Global Volunteer Emergency Response Center (CERT), delivering pro-bono cyber threat intelligence, vulnerability identification, incident response support, and lawful takedown of cybercriminal infrastructure to hospitals, the medical sector, and life-saving organizations (MS-LSO) worldwide. Its 1,500+ vetted volunteer members across 80+ countries collaborate via a private Slack workspace and security tool stack (Shodan, GreyNoise, VirusTotal) to neutralize cyber threats 24/7 across 22 timezones.
Is CTI League a public or private company?
CTI League is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was CTI League founded?
CTI League was founded in 2020. It employs 1,001 to 5,000 people.
Where is CTI League based?
CTI League is headquartered in New York, United States, in the North America region.
How does CTI League make money?
Two revenue lines are on record. Pro-bono volunteer services are the primary driver. The others are no commercial revenue streams.
Who are CTI League's main competitors?
Broad incumbents on record are Mandiant (Google Cloud) and CrowdStrike. Direct peers are Cyber Threat Alliance, Spamhaus Project, Health-ISAC, Global Cyber Alliance and Shadowserver Foundation. FS-ISAC is listed as a regional player. Emerging players are No More Ransom Project and Have I Been Pwned.
Does CTI League have an API?
No public API is recorded for CTI League.
What industry is CTI League in?
CTI League's product category is Cybersecurity Threat Intelligence Services. Its primary akta.pro industry code is BPAEADAC, Threat Intelligence Services, with a secondary code of HDADAJAN, Managed OT Security Services (MSSP/MDR for ICS/OT). Its NAICS code is 5616 and its SIC code is 7381.