Skip to content

ThreatBook

A Beijing-based threat intelligence and detection vendor, and the only Chinese company recognized in Gartner's threat intelligence market guide.

Visit Website ↗ + Add to Compare
55/100Incremental Innovator

Overview

ThreatBook is China’s earliest dedicated threat intelligence vendor, founded in 2015 to provide real-time threat data feeds and detection products aimed at blocking attacks before they execute rather than only investigating them afterward. Its product line has since expanded beyond pure intelligence feeds into network detection and response (NDR/XDR-style) tooling, sandboxing, and threat hunting platforms, following the broader industry trend of intelligence vendors building out detection products around their own data.

The company has been named in Gartner’s Market Guide for Security Threat Intelligence Products and Services across four consecutive editions, the only mainland Chinese vendor to appear there, which is a meaningful independent signal given how few China-based security vendors get evaluated by Western analyst firms at all. That visibility is largely a function of the scale of the Chinese domestic threat landscape ThreatBook’s intelligence is drawn from, which is simultaneously a strength (breadth of visibility into APT activity and infrastructure originating in the region) and a limitation for buyers outside China who need intelligence weighted toward their own regional threat actors.

Headquartered in Beijing, ThreatBook has raised roughly $190-208 million across multiple rounds from investors including CDH Investments, CICC Capital, and CITIC Securities, making it one of the best-funded threat intelligence vendors globally by disclosed capital, though nearly all of that funding and its primary customer base are domestic to China. For international CISOs, ThreatBook is most relevant as a data source on China-originating threat activity and regional attacker infrastructure rather than as a general-purpose detection platform, and organizations must weigh data-sovereignty and vendor-access considerations given the company’s China domicile.

Innovation Matrix Assessment

Innovation Velocity 6/10

Since its 2015 founding, ThreatBook has expanded from a pure threat-intelligence feed into NDR/XDR-style detection products and sandboxing, a natural and steady product expansion path typical of mature threat intel vendors, sustained by unusually large disclosed funding for the category.

Operational Value 7/10

ThreatBook has scaled to several hundred employees and operates detection infrastructure across its domestic market at meaningful scale, reflected in its inclusion across four consecutive editions of Gartner's Market Guide for Security Threat Intelligence Products and Services.

Market Momentum 6/10

ThreatBook has raised roughly $190-208 million across multiple rounds from institutional investors including CDH Investments, CICC Capital, and CITIC Securities, among the largest disclosed funding totals of any pure-play threat intelligence vendor globally, indicating strong domestic investor confidence.

Category Disruption 4/10

ThreatBook's approach follows the established threat-intelligence-plus-detection product pattern set by international peers rather than introducing a new methodology; its distinguishing factor is depth of visibility into China-originating threat activity rather than a novel technical approach.

Real-World Efficacy 6/10

Being named in Gartner's Market Guide for Security Threat Intelligence across four consecutive editions is a genuine independent signal of product quality, though this recognition is specifically about intelligence products and does not amount to independent detection-efficacy testing (e.g., MITRE ATT&CK evaluations).

Enduring Relevance 4/10

ThreatBook's intelligence is most valuable for visibility into China-based and China-originating threat activity; for international buyers outside that region its relevance is narrower, and data-sovereignty and vendor-access considerations around a China-domiciled vendor further limit adoption by Western enterprises and government agencies.

Why CISOs Should Care

CISOs whose organizations operate in or face threats originating from the China-based threat landscape may gain unique visibility from ThreatBook's regional intelligence, though this makes it a supplementary rather than primary intelligence source for most Western enterprises.

What Makes It Different

ThreatBook's differentiation is its depth of domestic Chinese threat-actor and infrastructure visibility and its unusually large capital base for a threat intelligence vendor, rather than a distinct detection methodology from Western competitors like Recorded Future or Mandiant.

The Matrix Verdict

55/100 — INCREMENTAL INNOVATOR

A well-funded and analyst-recognized threat intelligence vendor with genuine domestic-market strength, whose relevance to international CISOs is narrowed by geographic focus and by the data-sovereignty questions inherent in adopting a China-domiciled security vendor.

Editorial Note: Claims vs. Verified Findings

Vendor-sourced and unverified: ThreatBook's self-description as 'China's first' threat intelligence company and specific detection-accuracy figures are drawn from its own materials. Independently verifiable: the 2015 founding, Beijing headquarters, four-consecutive-edition inclusion in Gartner's Threat Intelligence Market Guide, and the ~$190-208M disclosed funding from CDH Investments, CICC Capital, and CITIC Securities are corroborated by Crunchbase and PitchBook third-party funding data.

Sources