Threat Intelligence Lab empowers organizations to build world-class Cyber Threat Intelligence (CTI) capabilities. We bridge the critical gap between raw threat data and actionable defense decisions.
Our Mission
We exist to make cyber threat intelligence accessible, actionable, and operationally relevant for organizations of every size. The threat landscape evolves daily — our mission is to ensure defenders evolve faster.
We believe that the most valuable intelligence is not the data you buy, but the intelligence you build from understanding your own attack surface, adversaries, and risk posture. We help organizations develop that capability.
Our Story
Threat Intelligence Lab founded in 2024 by Reza Rafati, a seasoned cybersecurity professional with over a decade of hands-on experience in AI, Cyber Threat Intelligence, Threat Hunting, and security operations. After years of seeing organizations struggle with the same challenges – fragmented threat data, unclear priorities, and a gap between security teams and decision-makers – Reza set out to build a company that would solve these problems at their root.
Starting from Rotterdam, The Netherlands, TIL has grown into a trusted partner for organizations across Europe and beyond. We are supported by our Advisory Board of industry experts, ensuring we remain at the forefront of cybersecurity practice.
What Sets Us Apart
Practitioner-Led, Not Vendor-Driven
We are practitioners first. Our team has built detection systems, created and maintained threat intelligence feeds, conducted large-scale malware analysis, led incident response engagements, and executed domain takedowns. We don’t just advise — we do the work.
Intelligence-Led Takedowns
Unlike traditional takedown services that react to reports, we use CTI to proactively identify and neutralize threats — from phishing infrastructure to botnet C2 servers. Our Cyber Takedowns service combines technical expertise with a global network of partners and law enforcement relationships.
Expertise
- Cyber Threat Intelligence (CTI) — Collection, processing, analysis, and dissemination of actionable threat intelligence
- Threat Hunting — Hypothesis-driven and intelligence-led hunting across enterprise environments
- Malware Analysis — Static and dynamic analysis at scale, reverse engineering
- Incident Response — Digital forensics, containment, eradication, and recovery
- Cyber Takedowns — Domain, phishing, botnet, and fraudulent infrastructure disruption
- Security Advisory — Board-level communication, strategy, and CTI program development
Values
- Evidence Over Hype — We ground every recommendation in verified data and proven methodology.
- Defender-First — Everything we build, write, and advise is designed to help defenders win.
- Transparency — We distinguish clearly between confirmed facts, assessments, and unknowns.
- Continuous Improvement — The threat landscape never stands still, and neither do we.
- Collaboration — We believe sharing intelligence makes everyone stronger. Our network of partners spans industry, academia, and law enforcement.
Company Information
Location: Rotterdam, The Netherlands
Founder & Owner: Reza Rafati
Dutch Chamber of Commerce (KvK): 92988334

