logo

REDTEAM.PL company

We are a company providing expert technical services in the the cyber security field. The company founders are professionals in various specializations of IT security, both offensive and defensive. It is not only our work, but also our passion for almost 20 years.

Get a quote

Why REDTEAM.PL services?

Clients choose REDTEAM.PL primarily because of our recognizable consultants and their documented track record. We have worked in cybersecurity since the late 1990s – over 25 years. We hold dozens of acknowledgements for responsibly disclosed vulnerabilities in widely used software and over 50 written client references. Adam Ziaja of REDTEAM.PL co-authored handbooks for the European Union Agency for Cybersecurity (ENISA) and wrote a book published by Polish Scientific Publishers PWN, while our research has been cited by the SANS Institute, Forbes magazine, CERT Polska and CERT Orange. All services are performed exclusively by experienced consultants – we never staff engagements with people lacking years of hands-on practice. We have also held Polish court-appointed expert witness status for well over a decade.

Cited by recognised authorities

Research by REDTEAM.PL has been cited by Forbes magazine (USA), the SANS Institute (USA), CERT Polska and CERT Orange. Adam Ziaja of REDTEAM.PL co-authored handbooks for ENISA – the European Union Agency for Cybersecurity. Links to the sources are below.

Forbes Magazine

Our discovery in US edition of Forbes. The prestigious magazine covered a vulnerability in Apple Safari discovered by our team, which allowed stealing user files.
Forbes Magazine

CERT Polska

BadWPAD research in CERT Polska annual report. Our detailed threat analysis was featured in the official yearly summary.
CERT Polska annual report

Google

$68,000 awarded by Google. We were honored for discovering critical vulnerabilities in the Chrome browser.
CVE-2020-6463 · CVE-2019-13766

RED TEAM (REDTEAM.PL)

RED TEAM was founded in early 2017 by two experienced and recognised IT security professionals – Adam Ziaja (OSCP since 2015, OSWP, eWPT) and Pawel Wylecial (OSCP since 2014, GXPN). As a result, the board of RED TEAM Sp. z o.o. consists solely of technical cybersecurity experts, who at the same time hold all of the shares, which means the company is entirely Polish-owned. At REDTEAM.PL you work directly with the founders, who take an active part in discussions, in supervising projects and in carrying out the work.

The quality of our services comes from over 25 years of interest and development across many aspects of IT security, which translates directly into the breadth of our knowledge. For that reason founding a company in this field was never purely a business for us but a passion we have devoted our free time to for years. Working with us means working directly with the owners: we take part personally and oversee every project, and our technical competence means that when we work alongside other experts in particular cybersecurity specialisations we are able to verify the quality of the work ourselves. Numerous references, available on request, confirm this – among them Allianz, CERT-EE, CERT.LV, Carefleet, Centralny Ośrodek Informatyki (the Polish Ministry of Digital Affairs IT centre), Europejski Fundusz Leasingowy (EFL), GoSport, Instytut Pamięci Narodowej (the Institute of National Remembrance), Jerónimo Martins, Orbis (Accor), PKO Ubezpieczenia, Reserved (LPP), SeaChange, TELDAT and Telewizja Puls. We hold over 50 named references for the founders, who are also our lead consultants.

The professionalism of our consultants is backed by internationally recognised certifications, references from well-known organisations, academic publications and professional experience gained in senior technical roles at recognisable international companies, such as the Royal Bank of Scotland (RBS) banking group. The services we deliver are first and foremost our long-standing hobby, which is why we know so many subjects inside out. Without exception, all work is carried out only by highly qualified specialists.

Our expertise and professional ethics are also reflected in holding the office of court-appointed expert witness, which means that for authorised government bodies, the justice system and law enforcement we can issue expert opinions of relevance to criminal proceedings.

We are a founding member of the Polish cybersecurity cluster CyberMadeInPoland, coordinated by the Kosciuszko Institute.

Cybersecurity experts

We hold real, demonstrable expert competence in both attack – penetration testing, red teaming – and defence – DFIR, threat hunting and threat intelligence – and we combine them in a single team. Our professional experience in each of these specialisations exceeds five years, and we have worked in areas such as red teaming, DFIR and threat hunting since their early days in Poland. This follows from over 25 years in the industry and a passion for cybersecurity that turned into a way of life.

Over the last decade, under bug bounty programmes, we have received dozens of public acknowledgements from well-known international companies (among others Adobe, Apple, BlackBerry, Google, Microsoft, Netflix, Nokia, VMware and Yahoo) for responsibly disclosed software vulnerabilities. In 2019 and 2020 alone Google awarded us a total of USD 68,000 along with publicly available acknowledgements for reporting a series of critical vulnerabilities in the Chrome browser. In 2020 a vulnerability we found in an Apple mechanism was highlighted by the US-based SANS Institute and by Forbes magazine.

In 2020, at the invitation of the Singapore Ministry of Defence, we took part as an offensive team (red team) in the international exercise Critical Infrastructure Security Showdown 2020 (CISS2020-OL) organised by the Singapore University of Technology and Design (iTrust SUTD). The objective was to attack critical infrastructure in the form of a water treatment plant (SWaT). During the exercise we successfully broke through the IT defences and took direct control of the SCADA HMI system.

On the defensive side, in 2019 we received numerous acknowledgements from European CERT incident response teams, among them CERT Polska, the Estonian CERT and the Latvian CERT, for detecting and shutting down badWPAD – a global MiTM (Man-in-the-Middle) attack whose victims numbered millions of computers worldwide. Our research was described on the company techblog and was also highlighted by the SANS Institute in the United States. REDTEAM.PL CERT is a recognised incident response team and a member of Trusted Introducer, the largest international organisation bringing CERT teams together. We have also built RedEye, our own tool for threat hunting through the detection of anomalies in network traffic, which we offer in a SaaS (Software as a Service) model as part of our SOC.

Our record also includes academic publications: authorship of the book “Praktyczna analiza powłamaniowa” (Practical post-breach analysis, ISBN 9788301193478) published by Wydawnictwo Naukowe PWN, and co-authorship of close to ten publications of the European Union Agency for Cybersecurity (ENISA), issued to support European CSIRT (Computer Security Incident Response Team) units in protecting cyberspace.

Thanks to competence on both the offensive and the defensive side we offer services that demand broad expert experience – threat hunting, for instance, that is proactive threat discovery. We do not wait for an incident to escalate; we detect it at the outset, while the attack on the organisation’s infrastructure is still under way. We are among the few who draw on real experience that lets us both simulate hacking attacks more effectively and detect them, because we know the tools and methods attackers use. Knowledge of the software and techniques (TTPs – Tactics, Techniques, Procedures) used by attackers is the hardest part of detection, as recognised sources for threat hunters confirm – the Pyramid of Pain, for example, which describes the difficulties present in this relatively new area of cybersecurity.

Timeline

Below is a timeline of the milestones in our 9 years of activity:

  • April 2017 – operations begin as RED TEAM Adam Ziaja.
  • February 2018 – following rapid growth, RED TEAM Sp. z o.o. is incorporated (VAT ID 5252739138, KRS 0000718490, REGON 369466623) together with RED TEAM Sp. z o.o. Sp.k. (VAT ID 5252741307, KRS 0000720860, REGON 369574353).
  • April 2022 – the partner company RTFS Sp. z o.o. is founded (VAT ID 6343013181, KRS 0000985219, REGON 522817642), providing threat hunting services.
REDTEAM.PL at the Security Case Study conference, 2018

See the Competencies of Our Team

Our team identified and responsibly disclosed multiple critical and high rated vulnerabilities in widely used global products. Acknowledgements for reported vulnerabilities have come from Adobe, Apple, BlackBerry, Deutsche Telekom, eBay, GitLab, Google, Harvard University, LastPass, Microsoft, Netflix, Nokia, Oracle, SoundCloud, VMware, Yahoo, Yandex and Zynga, among others:

Acknowledgement from VMware for REDTEAM.PL vulnerability reports
Acknowledgement from Microsoft for REDTEAM.PL vulnerability reports
Acknowledgement from Apple for REDTEAM.PL vulnerability reports
Acknowledgement from Netflix for REDTEAM.PL vulnerability reports
Acknowledgement from Mozilla for REDTEAM.PL vulnerability reports
Acknowledgement from Google for REDTEAM.PL vulnerability reports

REDTEAM.PL client references