If it can be exploited,
we find it first.
A verified security-researcher network operating under written authorization, defined scope, evidence controls, and client-ready reporting.
The workflow layer for authorized security assessment.
HUNT is a compliance-first assessment platform — coordinating verified researchers, client-approved scopes, evidence records, triage workflows, and reports. Every engagement is bounded by written authorization and rules of engagement.
No vulnerability survives long enough to become a threat.
Full assessment workflow — from intake and scoping to evidence, triage, remediation tracking, and final reporting.
Pentest → 0-day → Exploit Chain
Full spectrum: reconnaissance, vulnerability discovery, controlled validated security testing, and kill-switch management — delivered as a single operational service rather than fragmented engagements.
Human + AI Attack Intelligence
AI-orchestrated red team campaigns mutate and retry attack chains at scale. Human operators command every decision point — autonomous tooling never executes without judgement in the loop.
Verified Researcher Network
Pre-vetted, contract-ready researchers across regions. Engagements require client authorization, scope, and applicable legal review.
Adversary Pursuit & Neutralisation
Active pursuit of APT infrastructure, command-and-control pre-emption, and controlled takedown of hostile assets — before they strike. Coordination with IFC0 fusion cells for handoff.
Responsible Vulnerability Research
Curated vulnerability research handled under responsible disclosure, retention controls, and client-approved remediation workflows.
Cyber Range & Wargaming
Full-fidelity adversary emulation environments for defender training, doctrine validation, and capability benchmarking — including continuous red-team-as-a-service against your own infrastructure.
Operating at nation-state scale.
Global security researcher network — vetted, contract-ready, deployable on demand.
Specialists trained in authorized assessment across cloud, mobile, ICS/OT, and bespoke environments.
Countries with active operator presence and jurisdictional legal cover.
From engagement authorisation to operators on-target, including pre-cleared infrastructure.
Follow-the-sun handoff between Dubai, Singapore, and Tallinn fusion centres.
Operator background screening to government clearance equivalents in UAE, IN, EU.
Where HUNT operates.
Regional operations coverage supports follow-the-sun assessment management, client communication, and evidence review.
Dubai · CENTCOM
Primary operations centre. MENA, Africa, and Central Asia coverage with documented engagement authority.
Singapore · INDOPACOM
Asia-Pacific hub. Engineering and tooling depth, large operator pool, integration with Epic Fury manufacturing.
Tallinn · EUCOM
Europe and trans-Atlantic operations. Co-located with NATO cyber alignment and EU jurisdictional access.
How working with HUNT begins.
Engagements move fast. Most principals are operational within ten working days of first contact, including all clearance and legal infrastructure.
Authorized Brief
Client intake covering assets, scope limits, testing windows, data handling, emergency contacts, and engagement authority.
Capability Match
Specialist team composition, infrastructure requirements, and operational tempo defined against the principal's specific objectives. Delivered within 72 hours of brief.
Authorisation & Legal
Scope, rules of engagement, researcher eligibility, and client authorization finalized before assessment work begins.
Deployment
Operators on-target within 72 hours of final authorisation. Continuous reporting cadence agreed upfront. Coordinated handoff with IFC0 fusion cells where intelligence overlap exists.
Continuous Operations
Long-term engagements maintain dedicated operator pools, persistent infrastructure, and direct line to principal command. Tempo and scope adjusted in real time.
Authorized by design.
UAE primary jurisdiction with operational presence under local legal cover in 60+ secondary jurisdictions. No five-eyes data residency.
Researcher identity, proof, and eligibility review with continuous compliance monitoring where required.
Assessment data and evidence are handled with access controls, retention rules, encryption, and audit logging.
Vulnerability research is handled through responsible disclosure, client authorization, and controlled reporting.
Engagements require written authorization, scope, rules of engagement, and applicable legal review.
Full operational audit trail available to authorising principal. Independent oversight available on request.
How HUNT connects.
HUNT integrates client intake, assessment workflow, evidence management, and secure communications into one reviewable process.
Triggers HUNT operations from intelligence signal. The intent detector that activates the executor.
Physical extension of cyber operations — drones for cyber-physical targets and on-target presence.
Secures HUNT communication channels with strong cryptography and controlled access.
Engage HUNT.
Capability briefs are conducted under confidentiality and authorization controls. Initial briefs require approximately 90 minutes; full engagement scoping completes within 10 working days.
If you can break it,
we want you on the inside.
HUNT is a verified researcher network for authorized security assessments — structured scopes, paid engagements, evidence controls, and reputation built through reviewed work.
A flag worth fighting under.
Many researchers want clearer scope, stronger authorization, and better evidence handling. HUNT provides a structured network where approved work, reputation, and client-ready reporting are connected.
What enlistment gets you.
This is not unmanaged freelance work. It is scoped, authorized assessment work with review, reporting, and progression.
Written Authorization
Every engagement requires documented client authorization, rules of engagement, and scope boundaries before work begins.
Paid On Capability
Engagement fees, artifact bounties, and standing retainers for ranked operators. Compensation tracks the scoring matrix — verified impact pays, noise does not.
Identity, Protected
Pseudonymous researcher identity with a Verified Researcher Passport. Your handle carries reputation while sensitive identity data remains access-controlled.
Real Scope, Real Evidence
Work on approved assets only, with controlled evidence submission, triage, and remediation tracking.
A Ladder That Climbs
Recruit to Principal's Circle. Rank is earned on verified artifacts, not tenure. Climb the House leaderboard and unlock command-track engagements.
Follow-the-Sun Crews
Plug into 24/7 handoff between Dubai, Singapore, and Tallinn. Operate in a crew, learn from leads, never carry an engagement alone.
We screen for judgement, not just skill.
“We do not enlist the loudest. We enlist the ones who can reach into hostile infrastructure, hold the access quietly, and know exactly when not to pull the trigger.”
HUNT Operator Doctrine · Clause 1Eleven specialist domains. Pick your ground, or prove you cross several: Cloud · Mobile · ICS/OT · Web · Hardware · Wireless · Social Engineering · Crypto · AI/ML · Comms · Embedded. Every applicant passes identity/proof review, technical validation, and ongoing compliance checks where required.
Rank is earned, never assigned.
Five tiers. You move on verified artifacts and engagement performance — scored, audited, and visible on the House leaderboard.
Verified impact pays. Noise does not.
Fifteen artifact types across five categories. Every submission is reviewed by a lead, scored, and logged to your passport. Points drive rank, retainers, and House standing.
You don't operate alone. You operate for a House.
Every operator is drafted into one of four Houses. Your artifacts add to your House total; the standing resets each operational quarter. Sample standing shown.
House Saber
House Cinder
House Vantage
House Ophir
One credential. Total cover.
RESEARCHER PASSPORT
HNT0000000<0AE2600000M<<<<<<<<<<<<04
The 3D Verified Researcher Passport is your identity inside the network.
ICAO-9303-compatible machine-readable zone. Front carries your handle, House, rank, and domain; back carries your verified artifact log and clearance posture. It is the only thing that travels — your real identity never does.
- Pseudonymous by default · sensitive identity data access-controlled
- Live artifact and points ledger bound to the passport
- Downloadable once issued · revocable on clearance change
- Begins in Pending Issuance state until your proving engagement clears
How you get in.
The portal moves fast and screens hard. Most applicants reach a decision within 72 hours of completing intake.
Intake
Encrypted application. Declare your domains, jurisdiction, and the work that proves you. No CV theatre — evidence only.
Identity Gate
Face-verification gate establishes a single human behind a single handle. Your real identity is sealed; your handle is born.
Proving Engagement
A scoped, sandboxed task against a HUNT cyber range. We watch how you think, not just whether you land it.
Clearance Screen
Background and eligibility screening under documented compliance protocols. Continuous monitoring begins here.
House Draft
You're drafted into a House and matched to a crew lead. Your passport issues from Pending into active state.
First Engagement
Cleared for live authorised work inside a crew. Your first verified artifacts hit the ledger.
Standing Operations
Climb the ladder, build your House total, and unlock retainers and command-track engagements.
Enlist in HUNT.
Intake is encrypted and screened under compliance controls. Applicants reach a decision target within 72 hours. If you can assess it responsibly, prove it.