badanie cyberbezpieczeństwa

Cybersecurity Research

As cybersecurity is our passion, we are constantly involved in various research projects related to the field. We work on defense and detection methods as well as we participate in bug bounty programs, perform vulnerability research and other offensive type of research.

Get a quote

Why REDTEAM.PL services?

Clients choose REDTEAM.PL primarily because of our recognizable consultants and their documented track record. We have worked in cybersecurity since the late 1990s – over 25 years. We hold dozens of acknowledgements for responsibly disclosed vulnerabilities in widely used software and over 50 written client references. Adam Ziaja of REDTEAM.PL co-authored handbooks for the European Union Agency for Cybersecurity (ENISA) and wrote a book published by Polish Scientific Publishers PWN, while our research has been cited by the SANS Institute, Forbes magazine, CERT Polska and CERT Orange. All services are performed exclusively by experienced consultants – we never staff engagements with people lacking years of hands-on practice. We have also held Polish court-appointed expert witness status for well over a decade.

Security vulnerabilities

We found and responsibly disclosed multiple vulnerabilities:

b
“Cybersecurity researchers at Warsaw-based RED TEAM discovered a flaw in the way Safari handles sharing actions. Click in Safari to share a cute kitten picture with a friend and you could unknowingly pass critical information about your system to an attacker”

A Bug In Apple’s Safari Browser Could Let Hackers Steal Your Files
Forbes Magazine

We have also received multiple credits from international companies and institutions to which we responsibly disclosed security issues: Adobe (2014), Apple (2012), Apple (2020), BlackBerry (2012), Deutsche Telekom, Google (2013), Harvard University, Netflix (2013), Nokia (2013), Reddit, SoundCloud, Yandex (2013).

Red teaming

The talk “Atak z wykorzystaniem kolizji DNS” (An attack using DNS collision), presented at the Sekurak Hacking Party conference. The presentation is based on our research and on the article “Internal domain name collision”, which came out of a red teaming engagement for a Polish financial institution.

DNS based threat hunting and DoH (DNS over HTTPS) by Adam Ziaja – As someone who has been advocating the detection of malicious activities via DNS for many years, I was dismayed when I found out about malicious use of DNS over HTTPS (DoH). This is a great technical primer for blue teamers to learn the ins and outs of DoH and how red teamers/adversaries can use it to bypass just about every single defense we have.”

Staff Picks for Splunk Security Reading
Splunk

Threat hunting – proactive intruder detection

Drawing on our years of experience in incident response and attack simulation, we built RedEye – a tool for detecting the most advanced cyberattacks. Proactive threat discovery (threat hunting) is delivered as part of our Security Operations Center (SOC) service.

Post-breach analysis

A book devoted to the technical aspects of computer forensics and post-breach analysis, “Praktyczna analiza powłamaniowa” (Practical post-breach analysis), Wydawnictwo Naukowe PWN (2017).

Techblog

On our techblog, located at blog.redteam.pl we share knowledge about various aspects of cybersecurity and demonstrate our competencies in the field.

Recently published articles:

See the Competencies of Our Team

Our team identified and responsibly disclosed multiple critical and high rated vulnerabilities in widely used global products. Acknowledgements for reported vulnerabilities have come from Adobe, Apple, BlackBerry, Deutsche Telekom, eBay, GitLab, Google, Harvard University, LastPass, Microsoft, Netflix, Nokia, Oracle, SoundCloud, VMware, Yahoo, Yandex and Zynga, among others:

Acknowledgement from VMware for REDTEAM.PL vulnerability reports
Acknowledgement from Mozilla for REDTEAM.PL vulnerability reports
Acknowledgement from Adobe for REDTEAM.PL vulnerability reports
Acknowledgement from Google for REDTEAM.PL vulnerability reports
Acknowledgement from Apple for REDTEAM.PL vulnerability reports
Acknowledgement from Netflix for REDTEAM.PL vulnerability reports

REDTEAM.PL client references