// OFFENSIVE SECURITY

Test your company before hackers do.

We test web applications and APIs, look for a path to Domain Admin in your network, and send phishing to your people before someone else does.

sysnetshield@redteam: ~
  • CRTO, Red Team Operator (Zero-Point Security)
  • CRTL, Red Team Lead (Zero-Point Security)
  • CPTS, HTB Certified Penetration Testing Specialist (Hack The Box)
  • CCPenX-AWS, Certified Cloud Pentesting eXpert-AWS (The SecOps Group)
  • CNPen, Certified Network Pentester (The SecOps Group)
  • C-AI/MLPen, Certified AI/ML Pentester (The SecOps Group)
  • CAPenX, Certified AppSec Pentesting eXpert (The SecOps Group)
  • WEB1, Web Application Pentester Level 1 (TryHackMe)

// 02 · TEAM

The founders of SYSNETSHIELD

Patrik Žák, Red Team Lead at SYSNETSHIELD

Patrik Žák

Co-founder · Red Team Lead

He leads red team operations and infrastructure tests and holds six certifications: CRTO and CRTL for red teaming, CPTS and CNPen for penetration testing, CCPenX-AWS for the cloud, and C-AI/MLPen for AI systems. He found an integer overflow in the unflatten() function of MikroTik RouterOS, published in the National Vulnerability Database (NVD) as CVE-2026-39042 at CVSS 7.5 (High).

Patrik Žák’s full profile
Juraj Daniš, penetration tester at SYSNETSHIELD

Juraj Daniš

Co-founder · Penetration Tester

He tests web applications and APIs: from authorization flaws to business logic that a scanner doesn’t flag on its own. He also works on the security of IoT devices and industrial OT systems. He holds four certifications: CRTO, CNPen, CAPenX, and WEB1, the last two aimed directly at application security.

Juraj Daniš’s full profile

// 03 · HOW WE WORK

Four steps from brief to verified remediation

  1. 01

    Scope and rules

    On the intro call we go through what will be tested: how many applications and roles, which IP ranges, and whether the test runs from the internet or from inside the network. The result is a brief with the scope and the dates of the work. We sign it before the first packet. Before you get in touch, you can look at the indicative effort per service and what makes up the price.

  2. 02

    Testing

    We use automation to map the attack surface. We look for vulnerabilities by hand. A scanner doesn’t know what each role in your application is supposed to see, so authorization and business logic flaws are left to a person. We follow PTES (Penetration Testing Execution Standard) and OWASP, and we map red team steps to MITRE ATT&CK.

  3. 03

    Report

    The report has two parts: an executive summary with the impact and the remediation priority, and a technical section with reproduction steps, evidence, and specific recommendations. If a finding is Critical, though, we report it to you right away.

  4. 04

    Retest

    After the fixes we go through the findings again and verify whether each fix holds even against an attempt to bypass it. You get an updated report with the status of every finding. That lets you demonstrate the remediation to a client or to an auditor checking what companies must do under Act No. 264/2025 Coll., on Cybersecurity (the Czech Cybersecurity Act).

// CONTACT

Test your company before hackers do.

Tell us what you want tested. We’ll get back to you and schedule a call to pin down scope, timing, and price.