DEVCORE
DEVCORE is a Taiwan-based offensive cybersecurity firm offering Red Team Assessment, Penetration Testing, OPSR, security consulting, and training to governments, financial institutions, semiconductor leaders, and e-commerce enterprises across Taiwan and internationally.
- Company typePrivate
- Founded2012
- HeadquartersTaipei, Taiwan
- Headcount11–50
- GTM typeB2B
- OfferingServices
What DEVCORE does
DEVCORE (戴夫寇爾) is a Taiwan-based, privately held offensive cybersecurity firm founded in November 2012 by a team of world-class white-hat hackers. It was the first company in Taiwan to formally launch Red Team Assessment services in November 2017 and is structured around five core service lines: Red Team Assessment (紅隊演練), Offensive Product Security Research (主動式產品安全研究/OPSR), Penetration Testing (滲透測試), Security Consulting (資安顧問服務), and Security Training (資安教育訓練). A sixth, channel-like offering — OffSec Advanced Training — operates through an August 2024 strategic partnership with OffSec to deliver expert-level certification courses (including EXP-401/OSEE) in Taiwan. The technology stack is built around proprietary red-team methodologies, an OPSR practice that assesses high-risk vulnerabilities across hardware, firmware, and software from an attacker perspective, and a research pipeline that has produced 400+ world-class vulnerability disclosures and 50+ international enterprise bug bounty awards.
The business model is professional services-led, with project-based, quote-based enterprise engagements — no public pricing. Revenue is generated primarily through consultative enterprise sales into government agencies, financial sector institutions, high-tech manufacturers (including TSMC and ASE Kaohsiung, which have both issued cybersecurity recognition), and e-commerce companies, with a smaller stream of licensing/royalty-style revenue through the OffSec training partnership. Go-to-market is direct enterprise sales augmented by thought-leadership marketing: a technical blog, an annual DEVCORE CONFERENCE (since 2019, currently held at the Taipei International Convention Center), a CVE disclosure list, an enterprise bug bounty reports portal, and an active speaking presence at Black Hat USA, DEFCON, HITCON, and HEXACON.
Operationally, DEVCORE is headquartered in Taipei, runs primary operations in Taiwan, was bootstrapped without disclosed institutional funding, and holds ISO 27001 certification (June 2019). The company maintains a deliberate talent-density model — a small bench of senior researchers including Orange Tsai (Principal Security Researcher, credited with ProxyLogon/ProxyShell), Angelboy (MSRC 2024 Top 100 Most Valuable Security Researcher, ranked #33 overall and #9 in Windows), and Shaolin (Red Team Director) — and invests in pipeline via scholarships at Fu Jen Catholic University, National Taiwan University of Science and Technology, and a National Cybersecurity Scholarship. Recent execution includes Master of Pwn titles at Pwn2Own Toronto 2022 and Pwn2Own Berlin 2026, where AI tools were used to accelerate vulnerability discovery.
DEVCORE firmographics
Firmographics- Name
- DEVCORE
- Legal name
- DEVCORE 戴夫寇爾股份有限公司
- Website
- https://devco.re
- Company type
- Private
- Founded year
- 2012
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- DEVCORE is a Taiwan-based offensive cybersecurity firm offering Red Team Assessment, Penetration Testing, OPSR, security consulting, and training to governments, financial institutions, semiconductor leaders, and e-commerce enterprises across Taiwan and internationally.
- Ownership category
- akta.pro rank
DEVCORE industry classification
Industry- Product category
- Offensive Cybersecurity Services
- NAICS
- Computer Systems Design and Related Services (5415)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKADAE)
- akta.pro secondary industries
- Penetration Testing & Red Teaming (BPAKAHAF), Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH)
Keywords
Where DEVCORE is headquartered
LocationHeadquarters
- HQ city
- Taipei
- HQ country
- Taiwan
- HQ region
- Asia
Offices1 record
Markets served
DEVCORE business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure, Others
Revenue model
- Professional Cybersecurity Services: DEVCORE generates revenue primarily through professional cybersecurity services including Red Team Assessment, Penetration Testing, Security Consulting, and Security Training. These are consultative, project-based engagements targeting enterprise customers.
- OffSec Training Partnership: DEVCORE partners with global cybersecurity training and certification provider OffSec to offer Live Training (instructor-led in-person and online courses) and certification resources, generating revenue through training course delivery.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels6 records
DEVCORE product offering
Product offeringCore offering
DEVCORE provides professional offensive cybersecurity services to enterprise and government clients. Its offerings include Red Team Assessment (simulating real-world attacks to identify vulnerabilities), Penetration Testing, Security Consulting, Offensive Product Security Research (vulnerability analysis of hardware, firmware, and software), and Security Training. The company leverages its proprietary red team methodologies and vulnerability research to help organizations identify security gaps, validate defenses, and build effective security strategies.
Product overview
DEVCORE (戴夫寇爾) is a Taiwan-based cybersecurity company founded by world-class white hat hackers. It offers a portfolio of offensive cybersecurity services including Red Team Assessment, Penetration Testing, Security Consulting, Security Training, and Offensive Product Security Research, plus a partnership with OffSec for structured certification training (OffSec Advanced Training). DEVCORE also hosts an annual technical conference (DEVCORE CONFERENCE) focused on offensive security research and attack techniques. The company focuses on proactive attack-driven security rather than passive defense.
Differentiator
Problem solved
Functional benefit
Products and services
- Red Team Assessment Simulation of real-world cyber attacks to identify vulnerabilities and achieve enterprise-defined exercise objectives without disrupting business operations. Provides potential attack scenario analysis, intrusion path discovery, vulnerability patching guidance, customized defense strategies, and attack timelines. Designed for enterprise and government customers seeking realistic assessments of their defense readiness.
- Offensive Product Security Research (OPSR) Assesses high-risk vulnerabilities across hardware, firmware, and software from an attacker's perspective. Analyzes product core architecture and trust boundaries, prioritizes remediation of high-risk attack surfaces, and builds secure coding awareness within product teams. Targeted at product security teams and PSIRT functions at technology vendors and manufacturers.
- Penetration Testing Infiltration of designated enterprise systems using hacker mindset and techniques to uncover potential vulnerabilities and assess risks or damages. Includes comprehensive testing based on system complexity, discovery of complex attack techniques, rapid vulnerability mitigation, patch effectiveness verification, and universal secure programming recommendations. Targeted at enterprise organizations.
- Security Consulting Consultation on resource distribution and long-term defensive strategies from an attacker's perspective. Includes attack path analysis and security resource prioritization to help enterprises build effective defense strategies. Targeted at enterprise and government organizations seeking strategic security guidance.
- Security Training Training on defending and preventing incidents with the hacker mindset. Includes understanding attacker infiltration routes and context, hands-on practice for attack capability enhancement, practical attack techniques, and analysis of latest trends and techniques. Targeted at enterprise security teams and cybersecurity professionals.
- OffSec Advanced Training Structured in-person (OffSec Live Training) and online training featuring up-to-date offensive security skills, with OffSec certification and resources. Authorized delivery of OffSec's expert-level courses including EXP-401 (OSEE). Targeted at cybersecurity professionals seeking advanced offensive security certifications.
- DEVCORE CONFERENCE DEVCORE's annual technical conference focused on offensive security research, red team insights, novel attack vectors from real-world operations, and industry discussions on offensive cybersecurity topics. Includes enterprise-focused tracks and hacker-focused technical tracks. Targeted at cybersecurity professionals, researchers, and enterprise security teams.
Quantifiable outcome
- 77% of red team projects achieved internal network access
- +4 more outcomes
Companies that use DEVCORE
Customer profileNamed customers4 records
Segments3 records
Ideal customer profiles5 records
DEVCORE technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability1 record
Feature3 records
DEVCORE partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- OffSecflagshipDEVCORE partnered with global cybersecurity training and certification provider OffSec to host the first OffSec Live Training in Taiwan. This collaboration provides structured in-person (OffSec Live Training) and online training featuring up-to-date offensive security skills, with OffSec certification and learning resources. DEVCORE is authorized to deliver OffSec's expert-level courses including EXP-401 (OSEE).
Scale indicators7 records
Recent moves6 records
Expansion highlights6 records
DEVCORE competitors and assessment
Company assessmentDirect peers
- Bishop Fox: US-based boutique offensive-security firm offering red team assessments, penetration testing, and product security research for large enterprises. Closest US analogue to DEVCORE in positioning around attacker-led engagements and elite technical talent.
- Cure53: Berlin-based boutique firm specialising in penetration testing, application security, and vulnerability research for web and browser technology vendors. Directly comparable to DEVCORE's OPSR-style security research and consulting depth for technology product teams.
- IOActive: Global offensive security services firm with deep hardware, IoT, and connected-product testing in addition to enterprise pentesting. Comparable to DEVCORE's OPSR-style hardware/firmware/software coverage and published vulnerability research.
- Trail of Bits: US-based security research and consulting firm providing offensive security audits, vulnerability research, and security engineering for technology clients. Highly comparable to DEVCORE in tech-forward research posture and enterprise / product-security client work.
- NetSPI: US-based offensive security firm offering pentesting, red teaming, and attack surface management, including a software platform for managing pentest programmes. Closest peer in the pentest/red-team services plus platform model.
Broad incumbents
- Mandiant (Google Cloud): Now part of Google Cloud, Mandiant operates a large incident response, threat intelligence, and offensive security services practice at global scale. Comparable to DEVCORE on red team and vulnerability research capabilities, but with significantly larger breadth.
- NCC Group: UK-listed cybersecurity consultancy offering a broad portfolio including offensive security, incident response, managed detection, and software resilience. Comparable to DEVCORE on red team/pentesting and global enterprise customer base, but with a much wider service range and public listing.
- WithSecure (formerly F-Secure / MWR Labs): Helsinki-listed cybersecurity firm combining offensive security consulting (originally MWR Labs) with broad endpoint/cloud security products. Comparable to DEVCORE on the consulting side while operating a much larger commercial footprint.
Emerging players
- Synack: US-based platform company combining a vetted researcher community with managed pentesting and continuous attack-surface testing. Overlaps with DEVCORE's pentesting/red team services for enterprise buyers, but delivers work through a platform rather than in-house consultants.
Others
- Offensive Security (OffSec): Global training and certification provider behind OSCP/OSEE; DEVCORE is an authorised training partner for OffSec Live in Taiwan. Comparable adjacent player in the offensive security ecosystem — same buyer audience and similar methodologies — but focused on training/content rather than professional services.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
DEVCORE social profiles
Digital presenceDEVCORE compliance and trust
Trust signalCompliance1 record
DEVCORE financial estimates
Financial estimateRevenue estimate
Valuation estimate
DEVCORE leadership team
Management profileNumber of profiles
Profiles4 records
DEVCORE funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
DEVCORE M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about DEVCORE
What does DEVCORE do?
DEVCORE provides professional offensive cybersecurity services to enterprise and government clients. Its offerings include Red Team Assessment (simulating real-world attacks to identify vulnerabilities), Penetration Testing, Security Consulting, Offensive Product Security Research (vulnerability analysis of hardware, firmware, and software), and Security Training. The company leverages its proprietary red team methodologies and vulnerability research to help organizations identify security gaps, validate defenses, and build effective security strategies.
Is DEVCORE a public or private company?
DEVCORE is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was DEVCORE founded?
DEVCORE was founded in 2012. It employs 11 to 50 people.
Where is DEVCORE based?
DEVCORE is headquartered in Taipei, Taiwan, in the Asia region.
How does DEVCORE make money?
Two revenue lines are on record. Professional Cybersecurity Services are the primary driver. The others are offSec Training Partnership.
Who are DEVCORE's main competitors?
Direct peers on record are Bishop Fox, Cure53, IOActive, Trail of Bits and NetSPI. Broad incumbents are Mandiant (Google Cloud), NCC Group and WithSecure (formerly F-Secure / MWR Labs). Synack is listed as an emerging player. Offensive Security (OffSec) is listed as an others.
Does DEVCORE have an API?
No public API is recorded for DEVCORE.
What industry is DEVCORE in?
DEVCORE's product category is Offensive Cybersecurity Services. Its primary akta.pro industry code is BPAKADAE, Penetration Testing & Red Teaming, with a secondary code of BPAKAHAF, Penetration Testing & Red Teaming. Its NAICS code is 5415.