Blog

Writing

Opinions, analysis, and insights from real engagements. No vendor fluff.

Latest Posts

All Posts

Evasion
Oct 24, 2024 Vid Grosek

AMSI Bypass Techniques: PowerShell and Beyond

Understanding and testing the Antimalware Scan Interface.

Read More
Evasion
Oct 19, 2024 Vid Grosek

EDR Evasion Fundamentals: Understanding Detection

How EDR solutions detect threats and principles for evasion testing.

Read More
Web Security
Oct 14, 2024 Vid Grosek

Container Security: Breaking Out of Docker

Testing container security and common escape techniques.

Read More
Web Security
Oct 09, 2024 Vid Grosek

SQL Injection in 2025: Still Dangerous, Still Common

Why SQL injection persists and how to find it in modern applications.

Read More
Web Security
Oct 04, 2024 Vid Grosek

XSS in Modern Applications: Beyond Basic Payloads

Finding XSS in React, Angular, and other modern frameworks.

Read More
Web Security
Sep 29, 2024 Vid Grosek

AWS Security Testing: IAM, S3, and Beyond

Key areas to focus on when testing AWS environments.

Read More
Web Security
Sep 24, 2024 Vid Grosek

Azure AD Security: Common Misconfigurations

Security issues in Azure Active Directory deployments.

Read More
Web Security
Sep 19, 2024 Vid Grosek

GraphQL Security: Beyond REST Vulnerabilities

Unique security challenges in GraphQL implementations.

Read More
Web Security
Sep 14, 2024 Vid Grosek

JWT Security: Common Mistakes and How to Exploit Them

Testing JSON Web Token implementations for security flaws.

Read More
Web Security
Sep 09, 2024 Vid Grosek

SSRF Attacks: Making Servers Attack Themselves

Server-Side Request Forgery and its impact on cloud environments.

Read More

Explore More

Read my expertise pages, research, or prepare for a pentest.

Expertise Research Pentest Preparation

Have Security Questions?

I help companies understand their risks and fix them.

Get in Touch