Uploaded August 2025 | Updated September 2026, 1 hour ago
Krzysztof Zając (CERT PL, PL)
Senior Threat Analysis Specialist at CERT PL, currently working on automated vulnerability discovery techniques. Before becoming a security specialist, he was a software engineer with more than ten years of experience. Teaches offensive security at the University of Warsaw. Formerly a CTF player, playing with the p4 CTF team. Likes cats and bad puns.
--
Since the beginning of 2023, CERT PL has been periodically scanning more than 900 thousand domains and IP addresses of universities, hospitals, government institutions, schools, banks and other organizations, and detecting hundreds of thousands of vulnerabilities and misconfigurations (including high-severity ones, such as SQL Injection, in important entities).For that task we built a custom tool: Artemis (github.com/CERT-Polska/Artemis). It checks various aspects of website security and builds easy-to-read messages informing organizations about the scanning results.During the presentation, I will show how Artemis works, what we are looking for, and most significantly - lessons we've learned during our large-scale scanning project. As the tool is open-source, I will touch upon how to set up your own scanning pipeline.
Krzysztof Zając (CERT PL, PL)
Senior Threat Analysis Specialist at CERT PL, currently working on automated vulnerability discovery techniques. Before becoming a security specialist, he was a software engineer with more than ten years of experience. Teaches offensive security at the University of Warsaw. Formerly a CTF player, playing with the p4 CTF team. Likes cats and bad puns.
--
Since the beginning of 2023, CERT PL has been periodically scanning more than 900 thousand domains and IP addresses of universities, hospitals, government institutions, schools, banks and other organizations, and detecting hundreds of thousands of vulnerabilities and misconfigurations (including high-severity ones, such as SQL Injection, in important entities).For that task we built a custom tool: Artemis (github.com/CERT-Polska/Artemis). It checks various aspects of website security and builds easy-to-read messages informing organizations about the scanning results.During the presentation, I will show how Artemis works, what we are looking for, and most significantly - lessons we've learned during our large-scale scanning project. As the tool is open-source, I will touch upon how to set up your own scanning pipeline.










