Security Audit

Security Audits

We perform a broad scope of technical audits related to cybersecuritysecurity testing, cloud security, vulnerability assessment, smart contracts audits, configuration audits and source code reviews.

Get a quote

See the Competencies of Our Team

Our team identified and responsibly disclosed multiple critical and high rated vulnerabilities in widely used global products. Acknowledgements for reported vulnerabilities have come from Adobe, Apple, BlackBerry, Deutsche Telekom, eBay, GitLab, Google, Harvard University, LastPass, Microsoft, Netflix, Nokia, Oracle, SoundCloud, VMware, Yahoo, Yandex and Zynga, among others:

Acknowledgement from Oracle for REDTEAM.PL vulnerability reports
Acknowledgement from VMware for REDTEAM.PL vulnerability reports
Acknowledgement from Microsoft for REDTEAM.PL vulnerability reports
Acknowledgement from Netflix for REDTEAM.PL vulnerability reports
Acknowledgement from Adobe for REDTEAM.PL vulnerability reports
Acknowledgement from Apple for REDTEAM.PL vulnerability reports

Cybersecurity audit

Security audits of IT systems are done to confirm, that the infrastructure deployed in the organization fulfils security requirements and does not contain security vulnerabilities compromising the confidentiality, integrity or availability.

Cloud security assessments

Currently most of the organisations use at least one public cloud (infrastructure as a serviceIaaS) provided by Amazon, Microsoft or Google. More and more frequently public clouds (AWS, Azure, GCP) are mixed with private clouds (OpenStack, local Kubernetes) in hybrid environments. Additionally, cloud environments are often very dynamic and created using infrastructure as a code (IaC) approach developed in CloudFormation or Terraform and many applications are created using serverless technologies (Lambda, Azure Functions, Google Cloud Functions). In those cases the underlying infrastructure is managed by the provider, but it does not mean the provider is fully responsible for everything (shared responsibility models), thus the security of the environment is still a concern of the organisation.

We deliver cloud security assessments of the most prominent public clouds: Amazon Web Services (AWS), Microsoft Azure, Google Cloud as well as private cloud solutions: OpenStack and Kubernetes clusters. The security analysis is focused on security misconfigurations and the compliancy with the best practices recommended by the cloud providers. We perform a manual verification of the most crucial elements like the identity and access management (IAM), critical services, infrastructure code (CloudFormation, Terraform) as well as readiness to handle incidents in the cloud (logging and monitoring).

Smart contract security audit

Before deploying a smart contract on a blockchain it is important to perform a security assessment in order to verify whether it does not contain security vulnerabilities. In a rapidly developing world of decentralized finance (DeFi, NFT) security issues are actively exploited by black hat hackers often resulting in significant loss of funds.

We perform white box security assessments (code security reviews) of smart contracts written in Solidity (e.g. Ethereum and EVM-based blockchains like for instance Binance Smart Chain), Rust (e.g. Terra and Solana). A security review focuses on issues such as theft and locking of funds, business logic errors, overflows/underflows and re-entracy attacks to name a few examples. We use a hybrid approach where auditors perform most of the work by manually reviewing the code with the help of automated tools – performing static and dynamic analysis.

AI security audit

We carry out artificial intelligence security audits (AI).

  • Prompt injection – attacks that manipulate the input in order to force unwanted responses from the model
  • Data poisoning – deliberate contamination of training data affecting the model’s behaviour
  • Model extraction – attempts by unauthorised parties to reconstruct the model
  • Adversarial examples – inputs designed to mislead the model on purpose
  • Context data leaks – unauthorised access to information held in the prompt or in conversation history
  • API and integration security – assessment of the points where the model meets the rest of the infrastructure

Secure SDLC and DevSecOps

We support software engineering with the following services, covering both architecture and implementation:

  • producing and advising on threat models for the target solution (threat modelling),
  • implementing and reviewing processes such as Secure SDLC (a process that helps raise the overall security of software at the architecture and implementation stage) and DevSecOps (a process that builds security into the standard DevOps model).

Remote work environment security review

We perform security evaluations of work from home (WfH) setups. On the user / employee side review of system builds and configuration reviews can be performed. Additionally applications used for conference calls, messaging, VPN clients and all other typical apps used in a remote work scenario can be assessed. On the employer side we can test the security posture of external infrastructure responsible for granting remote access e.g. VPN servers.

Security code review

Source code audits may be connected with a whitebox pentest or be delivered as a separate service. The code is verified for security vulnerabilities. The analysis is performed manually with aid from automated tools and custom scripting. We have experience in reviewing applications written in i.a. Bash/C/C++/Java/JavaScript/.NET/PHP/Python/Ruby.

IT security audit

When in need of conducting it security audit we recommend to perform the following: config and build review, penetration testing and optionally code review. In case of a smaller budget or if a pentest was never done before it might be a good idea to start with a vulnerability scan to eliminate low hanging fruits.

Security config review, build review

Config reviews and build reviews are performed on software solutions such as operating systems, services (e.g. HTTP). We verify the configuration in relation to security based on benchmarks such as NIST, CIS and recommendations from the vendor.

PCI DSS certification

We more than meet the recommendations of the PCI DSS Penetration Testing Guidance and perform penetration testing in line with the requirements of the PCI DSS standard.

Software engineering consulting

We support companies during the software development process on both architecture and implementation levels with the following services:

  • threat modeling for the customer software solution,
  • implementation and review of processes such as Secure SDLC (a process which aims to help improve the general state of software security in the stage of architecture and implementation) or DevSecOps (process which introduces security in a standard DevOps model).

Security testing

We carry out security testing of every kind, including web security audits (website security audits, web application security audits) and IT system security audits. We verify the defences of network infrastructure as well as of applications – web, mobile and client-server among them.

Vulnerability assessment

Vulnerability assessments are performed by automated tools, which identifies mostly already known security bugs, for which it has defined plugins. In the next phase identified vulnerabilities are manually verified by our pentesters in order to eliminate false positives.

Explore Our Offer

We deliver advanced technical consulting services covering multiple aspects of cybersecurity from red team to blue team. Thanks to a diverse experience in IT security we are able to look at a wider perspective during engagements. Our abilities come from many years of work experience in cybersecurity and are confirmed with certificates, publications, advisories and references from our customers.

REDTEAM.PL client references