Dunicot A cybersecurity consultancy and advisory firm.

Services · 13 lines

Cyber security services.

Offensive testing that finds what is wrong, detection and response capability for when something gets through, and the training that stops it recurring. Each line is scoped and reported independently, or combined into a single engagement that follows the attack path across all of them, which is how attackers move.

Service lines

Offensive testing

Finding what is wrong, before someone else does.

01 Web application penetration testing Authentication and session managementAuthorisation, IDOR and multi-tenant isolationBusiness logic and workflow abuse Authenticated, multi-role testing of your web application: the logic, the roles and the state transitions a scanner cannot reach. 02 API penetration testing Broken object-level authorisation (BOLA/IDOR)Broken function-level authorisation (BFLA)Mass assignment and parameter pollution REST, GraphQL and gRPC tested against the OWASP API Security Top 10, with object-level authorisation checked call by call. 03 Mobile application penetration testing Static analysis of decompiled source and resourcesHardcoded credentials, API keys and cryptographic materialInsecure local storage: keychain, keystore, shared preferences, SQLite, cache iOS and Android tested as a binary, as a running process and as a client of your backend because all three fail differently. 04 Cloud penetration testing IAM policy analysis and privilege escalation pathsOver-permissive roles, trust policies and cross-account accessExposed object storage, S3, Blob Storage, Cloud Storage AWS, Azure and GCP tested for the paths that get used: identity escalation, exposed storage and metadata reachable from your own application. 05 Internal and external network penetration testing Full port and service enumeration across in-scope rangesVulnerability identification and manual exploitationDefault, weak and reused credentials The perimeter from outside, and the path from one compromised workstation to domain administrator from inside. 06 Secure source code review Data-flow tracing from user-controlled input to dangerous sinksAuthentication and session management implementationAuthorisation and multi-tenancy enforcement Manual review with the source in hand: tracing user input to dangerous sinks, and reading the authorisation logic rather than guessing at it. 07 IoT and embedded device penetration testing Debug interface identification and access (UART, JTAG, SWD)Flash memory extraction and firmware recoveryFirmware unpacking, filesystem and binary analysis The device, its firmware, the radio it speaks and the cloud it reports to, a connected product is only as strong as the weakest of the four. 08 Red team and adversary simulation Objective-based adversary simulationExternal reconnaissance and initial accessPhishing and social engineering (where authorised) A goal, not a checklist: can we reach the crown jewels, and does anyone notice before we do?

Detection and response

Seeing it when it happens, and proving what it reached.

Capability building

Making sure the same finding does not come back next year.

Every engagement includes

01

Executive summary

One page for the people who approve budget: what was tested, what was found, what it means in business terms.

02

Technical findings

Each finding with severity, CVSS, affected component, full request and response, reproduction steps and a working proof of concept.

03

Attack chains

Where findings combine, the chain is written out end to end, from first request to demonstrated impact.

04

Remediation guidance

A specific fix for your stack and framework, with the corrected pattern, not a link to a generic reference page.

05

Audit mapping

Findings mapped to SOC 2, ISO 27001, PCI DSS, HIPAA and OWASP ASVS as applicable, so the report drops straight into an audit pack.

06

Retest and attestation

Every finding retested in a clean session after remediation, with a signed attestation letter for customers and auditors.

Not sure which line you need?

Describe the system and the deadline. Scoping is a conversation, not a form, and it costs nothing.