Blog

Security Blog & Insights

Written by Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester, based in Ljubljana.

Opinions, analysis, and insights from real engagements. No vendor fluff.

Latest Posts

All Posts

Evasion
Oct 24, 2024 Vid Grosek

AMSI Bypass Techniques: PowerShell and Beyond

How Microsoft's Antimalware Scan Interface works across script engines — and which log events reveal attacker bypass attempts.

Read More
Evasion
Oct 19, 2024 Vid Grosek

EDR Evasion Fundamentals: Understanding Detection

A defender-first breakdown of EDR detection layers — signatures, behavior, memory — mapped to MITRE ATT&CK TA0005.

Read More
Web Security
Oct 14, 2024 Vid Grosek

Container Security: Breaking Out of Docker

Container isolation breaks under --privileged, mounted Docker sockets, or shared kernel CVEs like Dirty Pipe. I walk through the escape vectors I test in every engagement.

Read More
Web Security
Oct 09, 2024 Vid Grosek

SQL Injection in 2025: Still Dangerous, Still Common

SQLi hides in ORDER BY clauses, ORM raw() calls, and batch imports — not just login forms. Learn the sqlmap techniques and manual methods I rely on in real pen tests.

Read More
Web Security
Oct 04, 2024 Vid Grosek

XSS in Modern Applications: Beyond Basic Payloads

XSS isn't dead in React or Angular — it moved to dangerouslySetInnerHTML, bypassURL, ng-bind-html, and DOM sink abuse. Here's how I find it in modern codebases.

Read More
Web Security
Sep 29, 2024 Vid Grosek

AWS Security Testing: IAM, S3, and Beyond

From wildcard IAM policies and exposed S3 buckets to EC2 metadata SSRF and role chaining — here's what I look for when testing AWS environments.

Read More
Web Security
Sep 24, 2024 Vid Grosek

Azure AD Security: Common Misconfigurations

Consent phishing, legacy auth protocols, guest account over-permissions, and weak Conditional Access policies are the Azure AD misconfigs I find most often in pen tests.

Read More
Web Security
Sep 19, 2024 Vid Grosek

GraphQL Security: Beyond REST Vulnerabilities

GraphQL's single endpoint and introspection feature create unique risks — batching abuse, IDOR through aliases, and schema enumeration need dedicated testing methodology.

Read More
Web Security
Sep 14, 2024 Vid Grosek

JWT Security: Common Mistakes and How to Exploit Them

Algorithm confusion, none-bypass, weak HMAC secrets, and key injection attacks make JWT one of the most exploitable auth mechanisms I test. Here's the full breakdown.

Read More
Web Security
Sep 09, 2024 Vid Grosek

SSRF Attacks: Making Servers Attack Themselves

Server-Side Request Forgery hits differently in cloud-native stacks — IMDS credential theft, internal port scanning, and blind SSRF via DNS callbacks explained.

Read More

Explore More

Read my expertise pages, research, or prepare for a pentest.

Expertise About Vid Grosek Research Pentest Preparation

Have Security Questions?

I help companies understand their risks and fix them.

Get in Touch