
Tailored cyber defence, adversary hunting, and AiTM proxy threat intelligence

Tailored cyber defence, adversary hunting, and AiTM proxy threat intelligence
The Entire Cybersecurity Market, One Prompt Away
Connect your AI assistant to ... tools and ... vendors. Ask anything about the cybersecurity market.
Lab539 is a cybersecurity company that provides tailored defence services designed around a client's specific architecture, workflows, and risk profile, including complex operational technology (OT) environments and bespoke enterprise systems. The company's work focuses on understanding how an adversary would target a given organisation and engineering controls beyond default security configurations to prevent those attacks. In addition to defence design, Lab539 conducts adversary hunting and disruption work. This involves investigating suspicious activity or threat infrastructure affecting clients, using offensive-minded investigation techniques to understand the threat and disrupt the infrastructure enabling it, distinct from traditional incident response. Lab539 also operates a proactive threat intelligence offering called the AiTM Feed, which identifies adversary-in-the-middle backend proxy infrastructure before it is used in attacks. Rather than tracking frontend phishing domains that change frequently, this service focuses on the more persistent backend infrastructure that supports these attacks, intending to allow customers to block threats before they are deployed. The company appears to work with organisations that have complex or specialised environments, including those with OT networks, and has participated in industry events such as CYBERUK, BSides OT, and 5GOT, where its founder has discussed OT network security. Lab539 combines consulting-style tailored defence work with a distinct threat intelligence product (AiTM Feed), indicating a hybrid business model.