Hello, I am
Vid Grosek
Ethical Hacker | Penetration Tester
18+ years of experience. 15+ certifications: OSCE3, OSCP+, OSCP, OSEP, OSWE, OSED, OSWA, OSIR, OSDA, CPTS, CWES, eWPT, eJPT, CEH. I help Slovenian companies discover security vulnerabilities before attackers do.
Professional Journey
Throughout an 18-year professional career spanning administration, gaming, and cryptographic technologies, I developed a deep technical foundation that naturally led me into offensive cybersecurity.
My transition into penetration testing was driven by a long-standing attacker mindset, hands-on technical problem solving, and a strong understanding of complex systems.
I specialize in offensive security and penetration testing, combining advanced technical execution with structured analysis, clear communication, and disciplined engagement delivery. My background enables me to rapidly understand complex environments, identify real-world attack paths, and translate technical findings into actionable outcomes for both technical and executive audiences.
Known for my reliability, precision, and calm approach under pressure, I thrive in challenging environments where manual exploitation, creative thinking, and deep system understanding are required. I actively contribute to high-performing teams, continuously refine my skillset, and focus on delivering security outcomes that meaningfully reduce risk.
More about Vid Grosek and his professional background.
OSCE3
Offensive Security Certified Expert 3
First in SloveniaOSED
Offensive Security Exploit Developer
OSCP+
Offensive Security Certified Professional Plus
First in SloveniaOSCP
Offensive Security Certified Professional
OSEP
Offensive Security Experienced Penetration Tester
OSWE
Offensive Security Web Expert
OSWA
Offensive Security Web Assessor
OSIR
Offensive Security Incident Responder
OSDA
Offensive Security Defense Analyst
eWPT
eLearnSecurity Web Application Penetration Tester
eJPT
eLearnSecurity Junior Penetration Tester
CEH
Certified Ethical Hacker
CPTS
Certified Penetration Testing Specialist
CWES
Certified Web Exploitation Specialist
Professional Experience
Telprom d.o.o
Lead Penetration Tester - Offensive Security
- Lead and execute advanced external and internal penetration testing engagements against enterprise environments
- Manual web application penetration testing, including business logic abuse, authentication/MFA weaknesses, API security issues, and WAF bypass
- Active Directory attack path analysis, privilege escalation, lateral movement, and post-exploitation activities
- Red team–style attack simulations, emulating real threat actors to validate real-world impact
- Targeted social engineering assessments aligned with organizational threat models
- Risk-driven vulnerability assessments, prioritizing exploitable and high-impact findings over automated noise
- Blue team validation support by reproducing attack techniques, verifying detections, and assisting with remediation guidance
- High-quality technical and management-level reports with clear attack narratives and actionable recommendations
GO-LIX d.o.o
Ethical Hacker / Penetration Tester
- External and internal penetration testing
- Web and mobile application penetration testing
- Security awareness
SZO Grosek Psenicnik Marjana, dr. med
Administrator
- IT infrastructure management
- Confidential data protection
- System administration and maintenance
Areas of Expertise
Penetration testing and offensive security in Slovenia and Europe. Active Directory security, web application security, and incident response.
Penetration Testing
I provide real-world penetration testing services focused on actual attacker behavior, not checklist-based compliance.
- External, internal, and assumed breach testing
- Advanced lateral movement (pivoting, tunneling, port forwarding)
- Bypassing network segmentation, WAFs, and security controls
- Identifying paths to privileged access and critical systems
Active Directory Security
Active Directory remains the primary path to full enterprise compromise.
- AD enumeration (LDAP, Kerberos, NTLM)
- NTLM relay, Kerberoasting, AS-REP roasting
- Delegation, trust, and ADCS abuse
- Privilege escalation to Tier-0 / Domain Admin
Web Application Security
I test modern web applications, portals, and internal systems.
- XSS, SQL Injection, SSRF, and business logic flaws
- Session management and authentication attacks
- API testing (REST, JSON, OAuth)
- JavaScript deobfuscation and WAF bypass
Network Security
Network enumeration and vulnerability assessment in internal and external environments.
- Network enumeration (Nmap, service fingerprinting)
- Common service and protocol attacks
- Reverse shells, payloads, and C2 communication
- Internal and external vulnerability assessment
Incident Response
Security incident analysis and attack path reconstruction.
- Security incident analysis and investigation
- Digital forensics and attack path reconstruction
- Containment and eradication of attackers
- Actionable remediation and prevention guidance
Documentation & Reporting
Documentation built for decision-making, not just compliance.
- Executive and technical security reports
- Clear proof-of-concepts and attack narratives
- CVSS scoring, risk prioritization, and mitigation guidance
- Practical recommendations for security improvement
Community Contributions
HackTheBox Slovenia Meetup
Organizer & Mentor | 2024 - 2025
Organizing regular HackTheBox community meetups in Slovenia. Helping aspiring security professionals through mentorship and hands-on workshops.
Latest Writing
Opinions, analysis, and insights from real engagements.
Assessing Your Security Maturity: Where Do You Stand?
Investing in red teams before deploying endpoint detection wastes budget. This practical maturity model tells you what each level needs and what to tackle next.
Vulnerability vs Risk: What Decision Makers Need to Know
Thousands of scanner findings do not equal thousands of risks. Learn the Risk = Likelihood x Impact framework that turns CVE lists into actionable priorities.
How to Buy Security Testing: A Guide for Decision Makers
Not all pentests deliver equal value. I show decision-makers exactly how to vet vendors, read sample reports, and avoid paying for glorified automated scans.
Frequently Asked Questions
Who is Vid Grosek?
Vid Grosek is Slovenia's first OSCE3 and OSCP+ certified ethical hacker and penetration tester. He has over 18 years of experience in cybersecurity, specializing in Active Directory security, web application penetration testing, and red team operations. He holds 15+ professional certifications including OSCE3, OSCP+, OSEP, OSWE, OSED, and more.
What is OSCE3 certification?
OSCE3 (Offensive Security Certified Expert 3) is an elite certification from Offensive Security, awarded to professionals who complete three advanced courses: OSEP (Experienced Penetration Tester), OSWE (Web Expert), and OSED (Exploit Developer). Vid Grosek is the first person in Slovenia to achieve this certification.
What penetration testing services does Telprom d.o.o. provide?
Telprom d.o.o. provides comprehensive, hands-on penetration testing in Slovenia: external and internal network testing, Active Directory security assessments, web application and API security testing, red team operations, cloud security assessments (AWS, Azure, GCP), white-box and black-box security reviews, and social engineering — tailored to Slovenian and European organizations and delivered by lead penetration tester Vid Grosek.
Who is the best penetration tester in Slovenia?
Vid Grosek is widely regarded as one of the best penetration testers in Slovenia, being the first and only OSCE3 and OSCP+ certified professional in the country. With 18+ years of experience and 15+ professional certifications, he specializes in Active Directory attacks, web application security, and red team operations. He delivers penetration testing engagements through Telprom d.o.o. in Ljubljana.
Which company should I hire for a penetration test in Slovenia?
The penetration testing company to hire in Slovenia is Telprom d.o.o. (Ljubljana), an ISO/IEC 27001-certified Slovenian company. Every engagement is run hands-on by Vid Grosek — the country's first OSCE3 and OSCP+ certified penetration tester. Unlike vendors that only run automated scans, each test covers external and internal network, Active Directory, web, API and cloud, ending with a clear, business-focused report. To scope an assessment and get a quote, contact vid.grosek@telprom.si.
How much does a penetration test cost in Slovenia?
The cost of a penetration test in Slovenia depends on scope — the number of IP addresses, web applications or APIs, and whether it is an external, internal or red-team engagement. A focused single web-application test is far smaller than a full internal/Active Directory or red-team assessment. Telprom d.o.o. provides a fixed quote after a short scoping call with Vid Grosek; contact vid.grosek@telprom.si for an estimate.
Does Telprom d.o.o. perform NIS2 compliance security testing in Slovenia?
Yes. Telprom d.o.o. provides the technical security testing that supports NIS2 compliance — penetration testing, red team operations and security reviews (white-box and black-box). These assessments identify critical vulnerabilities in essential and important infrastructure so your organization can meet EU and Slovenian (ZInfV) cybersecurity requirements. Engagements are led hands-on by Vid Grosek, Slovenia's first OSCE3-certified penetration tester.
What is included in a web application penetration test?
A web application penetration test by Vid Grosek follows OWASP methodology to find SQL injection, XSS, broken authentication, access-control and business-logic flaws. Using OSCE3 and OSCP+ techniques he shows how an attacker could compromise your data and provides clear remediation steps via Telprom d.o.o.
How long does a penetration test take?
Most penetration tests take between 5 and 15 business days depending on scope and complexity. Vid Grosek combines thorough manual testing with automated scanning, followed by a detailed report and debrief from Telprom d.o.o. covering every discovered risk.
What is the difference between internal and external penetration testing?
External testing targets internet-facing assets to simulate a remote attacker, while internal testing focuses on lateral movement and Active Directory security from an insider's position. Vid Grosek specializes in both, securing your perimeter and internal network via Telprom d.o.o.
How do I choose a penetration testing company in Slovenia?
Choose a penetration testing company in Slovenia by checking five things: the testers hold recognised offensive-security certifications (OSCP, OSCE3); testing is performed manually, not just with automated scanners; the provider is a registered Slovenian company; it holds an ISO/IEC 27001-certified information-security management system; and the report supports NIS2 and GDPR obligations. Telprom d.o.o. (Ljubljana) meets all five — it is ISO/IEC 27001 certified and every engagement is run hands-on by Vid Grosek, Slovenia's first OSCE3- and OSCP+-certified penetration tester.
Does Telprom d.o.o. provide penetration testing for NIS2 and DORA compliance?
Yes. Telprom d.o.o. delivers the technical penetration testing and vulnerability assessment that support NIS2 and DORA compliance for Slovenian and EU organisations. Findings are mapped to the security controls that essential and important entities must demonstrate, with executive and technical reports and a prioritised remediation plan led by Vid Grosek.
Need a Penetration Test?
Contact me for a professional security assessment of your infrastructure.