Security Blog & Insights
Written by Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester, based in Ljubljana.
Opinions, analysis, and insights from real engagements. No vendor fluff.
All Posts
Payload Obfuscation: Avoiding Signature Detection
Why a payload with a unique hash and no recognizable strings still runs the same attack — and how behavioral detection fills the gap.
Read MoreLiving Off the Land: Using Built-in Tools
certutil, mshta, regsvr32 — how attackers weaponize legitimate Windows binaries and which detection rules actually catch abuse.
Read MoreProcess Injection Techniques: Living in Memory
From CreateRemoteThread to advanced injection variants — why process injection defeats allowlists and where defenders can intercept it.
Read MoreAMSI Bypass Techniques: PowerShell and Beyond
How Microsoft's Antimalware Scan Interface works across script engines — and which log events reveal attacker bypass attempts.
Read MoreEDR Evasion Fundamentals: Understanding Detection
A defender-first breakdown of EDR detection layers — signatures, behavior, memory — mapped to MITRE ATT&CK TA0005.
Read MoreContainer Security: Breaking Out of Docker
Container isolation breaks under --privileged, mounted Docker sockets, or shared kernel CVEs like Dirty Pipe. I walk through the escape vectors I test in every engagement.
Read MoreSQL Injection in 2025: Still Dangerous, Still Common
SQLi hides in ORDER BY clauses, ORM raw() calls, and batch imports — not just login forms. Learn the sqlmap techniques and manual methods I rely on in real pen tests.
Read MoreXSS in Modern Applications: Beyond Basic Payloads
XSS isn't dead in React or Angular — it moved to dangerouslySetInnerHTML, bypassURL, ng-bind-html, and DOM sink abuse. Here's how I find it in modern codebases.
Read MoreAWS Security Testing: IAM, S3, and Beyond
From wildcard IAM policies and exposed S3 buckets to EC2 metadata SSRF and role chaining — here's what I look for when testing AWS environments.
Read MoreAzure AD Security: Common Misconfigurations
Consent phishing, legacy auth protocols, guest account over-permissions, and weak Conditional Access policies are the Azure AD misconfigs I find most often in pen tests.
Read MoreExplore More
Read my expertise pages, research, or prepare for a pentest.