Security Blog & Insights
Written by Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester, based in Ljubljana.
Opinions, analysis, and insights from real engagements. No vendor fluff.
All Posts
Security Metrics That Actually Matter
10,000 patches in a quarter looked impressive — until 95% were on dev machines. Here are the metrics that actually indicate security improvement.
Read MoreVulnerability Prioritization: Beyond CVSS Scores
Blindly following CVSS scores leads teams to fix the wrong things first. I share the contextual prioritization matrix I use across real engagements.
Read MoreCommunicating Security Risk to Executives
A 120-page report full of CVSS scores lost the CEO in seconds. Here's how I frame findings as business risk — downtime, revenue loss, reputation.
Read MoreWriting Effective Penetration Test Reports
A great pentest with a poor report delivers zero value. Learn the exact structure — exec summary, findings, remediation — that drives real change.
Read MorePhishing Evasion: Bypassing Email Security
How phishing evades secure email gateways, sandboxing, and DMARC — with practical hardening steps for every layer of your email stack.
Read MoreDefense Evasion: Hiding from Logs and Monitoring
Log clearing, surgical log modification, and anti-forensics — how attackers erase their tracks and what architecture stops them.
Read MoreNetwork Evasion: Hiding in Plain Sight
How attackers blend C2 traffic with DNS queries, HTTPS, and legitimate protocols — and which network anomalies betray them.
Read MorePayload Obfuscation: Avoiding Signature Detection
Why a payload with a unique hash and no recognizable strings still runs the same attack — and how behavioral detection fills the gap.
Read MoreLiving Off the Land: Using Built-in Tools
certutil, mshta, regsvr32 — how attackers weaponize legitimate Windows binaries and which detection rules actually catch abuse.
Read MoreProcess Injection Techniques: Living in Memory
From CreateRemoteThread to advanced injection variants — why process injection defeats allowlists and where defenders can intercept it.
Read MoreExplore More
Read my expertise pages, research, or prepare for a pentest.