Full-spectrum information security
Security software we build, GovPAM for privileged access and KeyCare Pass for password management, backed by one accountable team across prevention, detection and response: 24/7 security operations, offensive testing, threat hunting and security-first architecture, aligned to MITRE ATT&CK.
Security software we build
Two products designed, built and supported by Dark Pools: one for the accounts that can change everything, one for the credentials everyone uses every day.
Defensive: detect and respond
Offensive: prove what an attacker could do
Advisory: build the program and the architecture
Defend, detect, respond. Around the clock.
Dark Pools pairs round-the-clock security operations centers in the United States and Southern Africa with offensive security and hypothesis-driven threat hunting, backed by the same intelligence platform used by governments and financial institutions.
- 24/7 SOC monitoring from continental US and Southern African operations centers
- SIEM engineering: log ingestion, correlation and detection use cases
- Hypothesis-driven threat hunts mapped to MITRE ATT&CK
- Offensive security: penetration testing, red team and social engineering
- Risk-based vulnerability management with verified remediation
- vCISO advisory, compliance readiness and zero-trust architecture
Security as a design input, not an afterthought
Architecture consulting that maps business capability to data, application and technology layers, with governance and zero trust built in from the first diagram.
- TOGAF-aligned architecture across business, data, application and technology
- Zero-trust roadmaps: identity, segmentation and least privilege by design
- Cloud and hybrid security architecture with cross-domain controls
- Technology governance, standards and architecture review boards
Where we are brought in
Cybersecurity questions
Dark Pools provides 24/7 SOC-as-a-Service from US and Southern African operations centers, SIEM engineering and management, penetration testing and red teaming across web, API, mobile, network and cloud, continuous vulnerability management, MITRE ATT&CK-aligned threat hunting with dark-web monitoring, and advisory services including vCISO, ISO 27001, NIST and POPIA readiness and security-first enterprise architecture.
Take the next step
Around-the-clock watch, a rehearsed kill chain and a defensible architecture, from one accountable team.