Skip to main content

About

Security operations, built by people who also break things.

We run managed detection and response, and we run offensive security engagements. Keeping both disciplines in one team is a deliberate choice — each makes the other measurably better.

Attack paths are rarely a single exploit. They are a route through systems that each looked acceptable on their own.

Mission

Help organisations build practical, continuously improving cybersecurity defences without the cost and complexity of building a large internal security team.

Vision

Make enterprise-grade security operations accessible to organisations of every size in Pakistan — so the quality of your defence is not decided by the size of your security budget.

Background

Where this comes from.

CavemenTech began as a technical publication — write-ups on penetration testing, capture-the-flag work and applied security research, published openly at cavementech.com.

This services practice grew out of the same work. The recurring pattern in offensive engagements was not exotic exploitation — it was ordinary attack paths that nobody was watching for. Finding them once is useful. Detecting them continuously is what actually changes an organisation's exposure.

The other pattern was structural. Pakistani organisations facing real regulatory pressure from PTA, the State Bank and overseas customers were being offered either a compliance checkbox exercise or an enterprise contract priced for a different market. Very little in between actually defended anything.

That is the whole premise: run the offensive work and the monitoring together, price it in rupees, and scope it to what an organisation genuinely runs.

Team

The people who would work on your account.

A small team by design. You deal directly with the practitioners doing the work, not an account manager relaying messages to them.

  • Ammar Hassan

    Founder & Chief Executive Officer

    • CEH Master
    • MSIS
    • eJPT
    • CEI

    Featured by EC-Council as a top ethical hacker worldwide

    Offensive security practitioner and information security trainer. Holds an MS in Information Security from NUST alongside a Master of Computer Science, and teaches ethical hacking as an EC-Council Certified Instructor. Leads detection engineering, ensuring the SOC's detection content reflects how intrusions actually unfold rather than how they are documented.

    Also holds · EC-Council Certified Instructor · Microsoft SC-900 · Azure Administrator · HCIP · CNSP · CAP

    ammarhassan.me
  • Sarmad Idrees

    Offensive Security Lead

    • OSCP+

    Leads penetration testing engagements across network, web application and Active Directory environments. OSCP+ certification requires demonstrated, hands-on exploitation under exam conditions and ongoing renewal — the practical standard that separates verified capability from a scanner report.

  • Waqar

    Security Operations Lead

    • MSIS

    Runs day-to-day security operations: telemetry onboarding, alert triage, investigation and incident coordination. Holds an MS in Information Security, and owns the discipline that turns detection output into decisions customers can act on.

Why us

Both sides of the same problem, under one roof.

Defending an environment and attacking one require the same knowledge applied in opposite directions. Keeping both in one organisation is what makes each of them better.

Offensive Security Expertise

Our detection engineering is written by people who spend the rest of their time breaking into environments. We understand how compromises actually happen, not how they are described in vendor documentation.

Security Operations

Continuous monitoring, investigation and response — the operational discipline that turns security tooling into an actual defensive capability.

Practical Security

Recommendations are scoped to what your organisation can realistically implement, sequenced by risk reduction per unit of effort.

Human-Led

Automation handles scale and correlation. Judgement calls about whether something is an incident stay with an analyst.

Continuous Improvement

Every incident, hunt and offensive engagement produces detection content. Coverage compounds over time rather than going stale.

One Security Partner

Monitoring, testing and assurance under one organisation, so findings from one discipline immediately strengthen the others.

Case studies

Case studies coming soon.

We publish engagement write-ups only with client permission. Until we have it, this section stays empty rather than being filled with invented customers, logos or results.

Want to see relevant examples now?

Ask during scoping. We can walk you through anonymised, permission-cleared examples of the attack paths and detection gaps we most commonly find in environments like yours.

Next step

Work with us.

Start with a scoping conversation. We'll tell you what we'd do, what it would involve from your side, and whether we're the right fit.

  • 1Tell us about your environment
  • 2We scope what's actually needed
  • 3You get a written assessment plan