Who we are
Dunicot was founded in Karachi in 2018 to deliver security testing that organisations could act on. We are a team of 25+ certified security professionals, from offensive specialists to analysts and engineers, working from offices in Pakistan and the United States for clients across North America, Europe, the Gulf, South Asia and Africa.
Our work spans penetration testing and red teaming, threat hunting and malware analysis, digital forensics and incident response, and the security training that keeps an organisation’s own people from becoming the entry point. The common thread is evidence: every engagement ends with something demonstrated rather than asserted.
Why we exist
Most of what is sold as penetration testing in this market is a scan with a cover page. The economics reward it. A tool is run, a PDF is exported, a certificate is issued, and the organisations buying it usually cannot tell the difference until an incident makes the distinction expensive.
We built the firm to do the opposite of volume. Engagements are manual, authenticated and adversarial. Findings are reproduced before they are written down and pass an eight-check verification gate that we publish in full. Retesting is included, because a finding that is never re-verified is a finding you are only assuming was fixed.
Tooling contributes coverage. It never contributes findings. Engagement standard
The team
Security work is not one skill. Finding the authorisation check that was never written, pivoting from one workstation across a flat internal network, building the detection that catches the same move next time, and running the response when something already got through are four different trades. A firm staffed for only the first hands you a report and leaves. We built the bench so the work does not stop at the finding.
25+ certified professionals sit across the disciplines below.
| Discipline | What they do |
|---|---|
| Principal Consultant | Engagement standards, methodology, delivery review and escalation on every engagement. |
| Senior penetration testers | Web, API, mobile and cloud engagements; authenticated multi-role testing and chained exploitation. |
| Network and infrastructure specialists | Internal and external network testing, Active Directory attack paths, segmentation validation. |
| Red team operators | Objective-based adversary simulation, payload development, detection evasion and purple-team replay. |
| Detection engineers and analysts | Threat hunting, SIEM detection engineering, alert triage and threat intelligence translation. |
| Forensics and malware analysts | Incident response, disk and memory forensics, reverse engineering and indicator extraction. |
| Risk and assurance | Control effectiveness review, engineer-grade and auditor-grade reporting, retest attestation. |
Engagements are staffed from that bench rather than from whoever is free that week. The testers assigned to you are named during scoping and held to contractually, and you can ask for their certifications before you sign. Delivery is reviewed against the same engagement standard whoever runs it, which is what keeps a report consistent when the practice grows.
14 of the team are published by name, with the discipline each one works in, on the team page. Every certification held across the practice is listed by issuer, with licence numbers and verification links, on the credentials page.
The record
How we work
Feature map before vulnerability map
Roles, tenancies, billing states and admin surfaces get mapped before testing begins. An authorisation gap is a deviation from intent, and intent has to be understood before it can be violated.
Chains over singles
A self-XSS plus a CSRF plus a permissive CORS policy is three low findings on a scanner report and one account takeover in practice. Findings are escalated to their maximum realistic impact before they are rated.
Two readers, one report
Every report is written for the engineer who has to fix it and the auditor who has to file it. Trying to serve both in one voice fails both.
No hedging
If it could not be reproduced in a clean session, it does not go in the report. Phrases like “may be exploitable” transfer a tester’s uncertainty onto the client, and we do not use them.
Our values
Six of them, and each one is a thing we can be held to rather than a poster on a wall. Where a value would cost us an engagement, it still applies.
What we hold to
- Freedom
- We are independently owned, take no vendor commission, and sell no product. Nothing in a report is shaped by what we would earn from the fix.
- Partnership
- We say what your budget buys, including when the honest answer is that it does not cover what you need and you should spend it elsewhere first.
- Honesty
- Findings are reported at the severity they warrant, not the severity that reads better. A clean result is written up as a clean result, with the coverage that backs it.
- Team
- The testers assigned to your engagement are named at scoping and held to. No senior byline on a junior’s report, and no anonymous pool.
- Quality
- Every finding is reproduced in a clean session before it is written down, and retested after remediation before it is closed.
- Responsibility
- We hold live vulnerabilities in your systems. That data is handled under our own certified ISMS, kept only as long as the engagement needs it, and never used as a reference without your written consent.
Offices
Pakistan office
- Entity
- Dunicot Private Limited
- Address
- 21-C, Zamzama Commercial Lane, Phase V, D.H.A.
Karachi 75500, Pakistan - Hours
- Mo-Fr 09:00-18:00 · Asia/Karachi (GMT+5)
United States office
- Entity
- Dunicot LLC
- Address
- 80 N. Gould St
Sheridan, WY 82801, United States - Hours
- Mo-Fr 09:00-18:00 · America/Denver (GMT‑7)