REDTEAM.PL is a Polish cybersecurity company founded by Adam Ziaja and Pawel Wylecial. Our research has been cited by Forbes magazine, the SANS Institute, CERT Polska and CERT Orange, and Google awarded us USD 68,000 for critical vulnerabilities found in the Chrome browser. We hold over 50 written client references.
Our team identified and responsibly disclosed multiple critical and high rated vulnerabilities in widely used global products. Acknowledgements for reported vulnerabilities have come from Adobe, Apple, BlackBerry, Deutsche Telekom, eBay, GitLab, Google, Harvard University, LastPass, Microsoft, Netflix, Nokia, Oracle, SoundCloud, VMware, Yahoo, Yandex and Zynga, among others:
Cited by recognised authorities
Research by REDTEAM.PL has been cited by Forbes magazine (USA), the SANS Institute (USA), CERT Polska and CERT Orange. Adam Ziaja of REDTEAM.PL co-authored handbooks for ENISA – the European Union Agency for Cybersecurity. Links to the sources are below.
Forbes Magazine
Our discovery in US edition of Forbes. The prestigious magazine covered a vulnerability in Apple Safari discovered by our team, which allowed stealing user files. Forbes Magazine
BadWPAD research in CERT Polska annual report. Our detailed threat analysis was featured in the official yearly summary. CERT Polska annual report
Google
$68,000 awarded by Google. We were honored for discovering critical vulnerabilities in the Chrome browser. CVE-2020-6463 · CVE-2019-13766
Splunk
Recognised by a Splunk security strategist. Our attack scenario was featured by Splunk's global strategist as essential reading for blue teams. Staff Picks for Splunk Security Reading
Why choose us?
When choosing a cybersecurity service provider, wide competencies of consultants should be the priority – this is the crucial element with direct impact to service performance.
“I chose RED TEAM because of their positive feedback from prior customers, their swift and accurate response to my enquiry, and their reasonably priced services. RED TEAM identified a vulnerability that had not been identified by TWO previous penetration testing firms.”
Security Architect, Software Development Company from New York City — Clutch
What makes a mid-level specialist a branch expert? Is that a matter of a title? Practice and achievements on the field are making an expert also come together with wide appreciation in the market. This is the crucial feature which stands us out and clients choose us from other cybersecurity specialists. As one of a few companies we can boast substantive and verified information concerning our consultant competencies and experience. Entire team is composed of experts – we do not implement projects engaging inexperienced staff (e.g. students, interns etc). You can be sure that all tasks are performed by people whose profile you can find in our offer. We have been engaged in cybersecurity since late 90’ consequently we have more than 20 years of practice.
CERT Polska announced the takeover of the .pl domains used in the BadWPAD attack, carried out with our help (the post below is in Polish):
Z pomocą @redteampl przejęliśmy domeny w strefie .pl mogące zostać wykorzystane w podatności #BadWPAD. W najnowszym artykule opisujemy szczegóły techniczne podatności i zalecenia dla administratorów oraz użytkowników. https://t.co/mS9jXECNfc
“In 2019, Adam Ziaja published a series of articles on the use of BadWPAD in the .pl domain. [...] analysed the content of the wpad.dat file in successive years on the basis of the indexed content available at archive.org. It was found that due to the rules contained in the PAC file, requests to popular affiliate programs were resolved through the pointed proxy. [...] From 15 May to 22 May 2019, the CERT Polska sinkhole registered 6.5 million HTTP requests from approximately 40,000 unique IP addresses.”
Our team members were among the forerunners of now popular bug bounties designed for researchers to submit identified vulnerabilities. Last decade we have received dozens of acknowledgements for responsibly disclosed gaps in security from globally known organisations as Adobe, Apple, BlackBerry, Deutsche Telekom, eBay, Google, Harvard University, Microsoft, Netflix, Nokia, VMware, Yahoo or Yandex. We also received them as official references from Polish companies as Onet, Interia, Wirtualna Polska, Empik and Home.pl.
eBay Bug Bounty (2012)
VMware Bug Bounty (2013)
Yahoo Bug Bounty (2013)
At the turn of 2019/2020 we performed vulnerability research on the most popular web browser - Google Chrome and disclosed critical vulnerabilities (later named as CVE-2019-13766 and CVE-2020-6463) and gained award from Google enterprise with cumulative value $68,000.
Today i received some great swag from Google VRP, thanks! Also „Working as Intended” was pure gold :) pic.twitter.com/ukc7PdND9k
For the research on badWPAD attack we were not only honoured by CERT Poland (Polish computer emergency response team), CERT Orange and american institute SANS, but received acknowledgments from national european CERTs – estonian CERT-EE and latvian CERT.LV too. REDTEAM.PL CERT became internationally recognised in effect.
For years we managed many technical issues of broadly understood cybersecurity - both offensive and defensive - which is why we have a comprehensive approach. As early as in 2014 Adam Ziaja - Chairman of the Board was a member of a team of three that won Cyber Europe international workshops arranged by ENISA for CERTs. The SOC service (Security Operation Center) we offer is an effect of our 14 years professional experience in CERT and SOC. As a result we develop a new threat hunting, 24/7 high quality security monitoring tool – RedEye. In particular APT (Advanced Persistent Threat) offences can be disclosed using this tool. Moreover providing digital forensic and incident response we use certified hardware and software thus entrusted devices and evidence are treated appropriately. Furthermore for entitled parties formal forensic expertise can be delivered.
Over the last decade, we have repeatedly been speakers at recognized scientific conferences, such as Technical Aspects of ICT Crime (TAPT) organized by the Police Academy in Szczytno (WSPol), or Security Case Study organized by Polish Cybersecurity Foundation. Moreover, already in 2014, at the SyScan360 international conference held in Beijing, we presented the results of our research on mobile browser security. We also participated in debates as experts at, among others, the PolCAAT conference organized by the Institute of Internal Auditors IIA Poland.
In the REDTEAM.PL team we all have more than 10 years experience and one of the widest competencies on the market. Thanks to a professional and compliant approach we gain more than 50 official references for our cybersecurity service. Highest quality is our best advertisement and the reason why we are not using resources for marketing or sales campaigns. From 2017 we operate based only on widespread good opinion about our competencies and recommendations from satisfied clients.
As one of the very few cybersecurity companies, brocage in hardware sell or licenses cross selling (e.g. antivirus software) is not a part of our business strategy. We stay focused on providing information security technical services and make our recommendations or advice independent from product selling commision. We are capital self-contained as well – RED TEAM Sp. z o.o. share capital comes 100% from Board Members (Adam Ziaja and Paweł Wyleciał). Years of professional work and raised competencies in numerous aspects of cybersecurity, both offensive and defensive, enable us to have a wider view to IT security. Last years american institute SANS relied on research conducted by both of our Board Members.
We have worked in cybersecurity since the late 1990s – over 25 years. We have no investors and no sales department, and we do not spend on any form of conventional advertising, yet we have operated at scale as REDTEAM.PL for 9 years. Most of our clients come through referrals, which is also why we hold over 50 written, named references for completed work.
In 2022, after three years of working together on SOC services, we founded the company RTFS with our partner – the first Polish company dedicated to threat hunting, delivered using our own software RedEye.
Reaching REDTEAM.PL you will work directly with founders proactive in negotiation, execution and controlling stages of project activities. Be invited to cooperate with us!
Meet Our Team
The company founders have a rich professional experience, additionally confirmed with certificates recognised worldwide, publicly presented research, references and thanks from known companies such us Google, Microsoft, Apple (references available upon request).
Board member and a co-founder of REDTEAM.PL. For many years focused on mostly offensive security research and having many accomplishments in the field.
REDTEAM.PL carried out internal and external network penetration tests and personnel awareness tests (red teaming). The team showed great commitment as well as a proactive attitude and flexibility during testing. We recommend cooperation with REDTEAM.PL. — Orbis (Accor Group)
CERT.EE would like to thank REDTEAM.PL for the valuable information, which has helped us to improve security of IT resources of the Republic of Estonia. — Estonian National and Governmental CSIRT
REDTEAM.PL performs tasks in the field of security testing. The assignments are carried out on time and of high quality. — Center for Informatics Technology (Ministry of Digital Affairs)
REDTEAM.PL carried out penetration tests of software produced by TELDAT. The work was performed professionally, on time and with due diligence. The conclusions in the form of a report were precise and related to all areas of interest to the contracting party. — TELDAT
CERT.LV would like to thank REDTEAM.PL for the valuable information, which has helped us to improve security of IT resources of the Republic of Latvia. — Latvian National and Governmental CSIRT
REDTEAM.PL performed penetration testing of an online store. The work was completed on time, with due diligence and was of high quality. — GO Sport
REDTEAM.PL has performed penetration tests of the integration module with the payment operator of the Reserved online store. The work was completed on time and with due diligence, and the service provided was high quality. — Reserved (LPP)
We recommend REDTEAM.PL, the config review and penetration testing services requested by us were provided with the highest quality. The audit team demonstrated great commitment, professionalism and extensive knowledge. — Institute of National Remembrance (IPN)
We recommend cooperation with REDTEAM.PL for professionalism and full commitment in the provision of services related to the security of websites. — EFL Leasing (Crédit Agricole Group)
REDTEAM.PL performed penetration testing of a web application. The work was carried out in a timely manner, with due diligence and professional ethics. — PKO Życie TU (PKO Banking Group)
REDTEAM.PL performed penetration testing of a web application. Tests were carried out within the agreed timeframe and with due diligence. Results of the work provided in the report were understandable. — Allianz
REDTEAM.PL has performed penetration tests of a mobile application. The entrusted work has been carried out on time and with due diligence, which resulted in a high quality evaluation of the services provided. — Carefleet (Crédit Agricole Group)
REDTEAM.PL has performed logs and disk images analysis. Computer forensics service was performed on time and with due diligence. The delivered results in the form of a report were comprehensible.