// TEAM

Juraj Daniš tests web applications and APIs and also works on OT security

Juraj Daniš is a penetration tester and co-founder of SYSNETSHIELD, a Prague offensive security company. He tests web applications and APIs: from authorization flaws to business logic that a scanner doesn’t flag on its own. He co-founded the company with Patrik Žák in October 2023 and is its managing director and co-owner. What the company does and how engagements run is summed up on the whole team’s page.

Juraj Daniš, penetration tester at SYSNETSHIELD

// 01

What Juraj Daniš works on

A scanner reliably reports an outdated library or a missing header. But a user pulling up another company’s invoice by changing one digit in the URL is an authorization flaw, and that usually takes a manual pass through the application, role by role, to find. That is exactly what Juraj Daniš goes after: he walks through roles and permissions and tests the business logic, that is, the rules for what the application should allow and in what order.

He tests the APIs running underneath the application the same way. The service page describes what a web application test checks, and the service overview sums up how we run penetration tests, from agreed scope to the retest of fixes.

He also works on the security of IoT devices and industrial OT systems: from smart devices on the company network to the control systems that run manufacturing. These environments tolerate less than the web, so they are tested differently: carefully, and with live operations in mind. The service page describes how we approach tests of industrial control systems (OT/ICS).

// 02

Juraj Daniš’s four certifications

Juraj Daniš holds four certifications: CRTO (Red Team Operator) from Zero-Point Security, CNPen (Certified Network Pentester) and CAPenX (Certified AppSec Pentesting eXpert) from The SecOps Group, and WEB1 (Web Application Pentester Level 1) from TryHackMe. CAPenX and WEB1 both target application security: CAPenX is an expert-level exam, and WEB1 is built on hands-on testing of web applications.

// 03

Juraj Daniš’s articles on the blog

On the blog he is the named author of pieces that go deep where automation stops: what can be read out of the data stored on a phone, and why an active scan can bring a production line to a halt.

Updated .

// WORK WITH US

Tell us what you want tested

Tell us what you want tested. We’ll get back to you and schedule a call to pin down scope, timing, and price.