Company Performance Metrics
- John Fitzpatrick: Founder
Lab539 provides cybersecurity threat intelligence and protection services focused on adversary‑in‑the‑middle (AiTM) and related attack infrastructure. The company offers a Tailored Threat Intelligence approach that concentrates on risks and adversaries relevant to each client’s environment and technology stack. Lab539 develops and maintains an AiTM
Feed that tracks phishing kits, adversary infrastructure, and associated indicators, exposed through APIs. The platform integrates with Microsoft Defender and Conditional Access policies to automate blocking of malicious domains, IPs, and URLs. Lab539 supplies indicators of compromise for ransomware operations such as Akira, Linux malware hashes, and leaked payment card data to support detection and response teams. The portal and APIs enable security teams to manage indicators, retrieve machine‑readable threat data, and embed it into existing security workflows. This focus aims to improve organisations’ ability to protect critical assets by operationalising current and highly targeted threat intelligence.