Certifications
-
ISO/IEC 27001 certified ISMS
Dunicot Private Limited
-
OffSec Certified Professional (OSCP)
OffSec
-
OffSec Web Expert (OSWE)
OffSec
-
CREST certified
CREST
-
Licensed Penetration Tester (Master)
EC-Council
-
Certified Penetration Testing Professional
EC-Council
-
Certified Ethical Hacker
EC-Council
-
Practical Network Penetration Tester
TCM Security
-
Certified Information Systems Auditor
ISACA
-
Certified Information Security Manager
ISACA
-
CompTIA Advanced Security Practitioner
CompTIA
-
AWS Certified Security Specialty
Amazon Web Services
-
Azure Security Engineer Associate
Microsoft
-
Fortinet Certified in Cybersecurity
Fortinet
-
Fortinet Certified in Network Security
Fortinet
-
Cisco Certified Network Associate
Cisco
16 active certifications: the firm’s own ISO/IEC 27001 ISMS, and fifteen held by individuals across offensive security, cloud, audit and governance. Each of the individual certifications is verifiable on the issuing authority’s own portal, and the ISO certificate and scope statement are provided on request under NDA.
| Certification | Issuer |
|---|---|
| OffSec Certified Professional | OffSec |
| OffSec Web Expert | OffSec |
| CREST certified | CREST |
| Licensed Penetration Tester (Master) | EC-Council |
| Certified Penetration Testing Professional | EC-Council |
| Certified Ethical Hacker (v12) | EC-Council |
| Practical Network Penetration Tester | TCM Security |
| Certified Information Systems Auditor | ISACA |
| Certified Information Security Manager | ISACA |
| CompTIA Advanced Security Practitioner | CompTIA |
| AWS Certified Security Specialty | Amazon Web Services |
| Azure Security Engineer Associate | Microsoft |
| Fortinet Certified in Cybersecurity | Fortinet |
| Fortinet Certified in Network Security | Fortinet |
| Cisco Certified Network Associate | Cisco |
Practice certification
- Organisation
- Dunicot Private Limited
- Standard
- ISO/IEC 27001
- Evidence
- Certificate and scope statement provided on request under NDA
Research record
Hall of Fame acknowledgements
Organisations that have publicly credited our team for responsible disclosure. These are acknowledgements of security research, not client engagements and not partnerships. The distinction matters and is stated here deliberately.












- U.S. Dept. of Defense





- ESET





- Caviar





- Schuberg Philis





- Inkmonk





- Microsoft
- U.S. Department of Defense
- GitHub
- Intel
- Apple
- Sony
- Salesforce
- SAP
- Booking.com
- Starbucks
- BuzzFeed
- Docker Hub
- DoorDash
- Zomato
- ESET
- Malwarebytes
- AVG
- ABN AMRO Bank
- Grab
- New Relic
- Recorded Future
- HackerRank
- Sky TV
- Blockchain.org
- ShowMax
- Caviar
- Quantopian
- Freelancer
- MediaFire
- Bitcasa
- Schuberg Philis
- Issuu
- Inflectra
- Constant Contact
- Transloadit
- FunCaptcha
- OpenDrive
- Inkmonk
- Panorama9
- Resin.io
- Balsamiq
Press coverage
- Khaleej Times Did Careem ignore advice on security breach vulnerabilities? 2018
- Gulf News Careem notified of vulnerabilities as early as 2016: Experts 2018
- Databreaches.net Careem knew — or should have known — they had a serious problem 2018
- MenaBytes Careem was informed about their security vulnerabilities in June 2017 2018
- Zawya Pakistani researcher said he “penetrated Careem’s apps” 2018
- Digital Rights Monitor Ethical hacker Daniyal Nasir was able to access data 2018
Questions
Who will perform our penetration test?
Named, certified testers from our team, agreed with you during scoping and held to contractually. Not an anonymous pool, and not juniors working under a senior's byline. You can ask for the CVs and certifications of everyone assigned before you sign, and delivery is reviewed by our Principal Consultant. The certifications held across the team are listed on the credentials page.
What is a HackerOne Top 100 ranking?
HackerOne’s all-time leaderboard ranks researchers by reputation accumulated from valid, triaged vulnerability reports across public bug bounty programs. It is earned from findings that companies validated and paid for, which makes it one of the few security credentials that reflects demonstrated results rather than an examination.
Which companies have publicly acknowledged your vulnerability disclosures?
Public Hall of Fame acknowledgements include Microsoft, the U.S. Department of Defense, GitHub, Intel, SAP, Booking.com, Starbucks, Docker Hub, DoorDash, Grab, ABN AMRO Bank, New Relic, ESET, Malwarebytes and more than eighty others, 100+ documented in total. These are public acknowledgements of responsible disclosure, not client engagements.
Has Dunicot’s security research been covered in the media?
Yes. The best known is the 2018 disclosure that data belonging to 1.4 million Careem drivers was exposed, covered by Khaleej Times, Gulf News, Databreaches.net, MenaBytes and Zawya.