Blog

Security Blog & Insights

Written by Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester, based in Ljubljana.

Opinions, analysis, and insights from real engagements. No vendor fluff.

Latest Posts

All Posts

Evasion
Nov 08, 2024 Vid Grosek

Payload Obfuscation: Avoiding Signature Detection

Why a payload with a unique hash and no recognizable strings still runs the same attack — and how behavioral detection fills the gap.

Read More
Evasion
Nov 03, 2024 Vid Grosek

Living Off the Land: Using Built-in Tools

certutil, mshta, regsvr32 — how attackers weaponize legitimate Windows binaries and which detection rules actually catch abuse.

Read More
Evasion
Oct 29, 2024 Vid Grosek

Process Injection Techniques: Living in Memory

From CreateRemoteThread to advanced injection variants — why process injection defeats allowlists and where defenders can intercept it.

Read More
Evasion
Oct 24, 2024 Vid Grosek

AMSI Bypass Techniques: PowerShell and Beyond

How Microsoft's Antimalware Scan Interface works across script engines — and which log events reveal attacker bypass attempts.

Read More
Evasion
Oct 19, 2024 Vid Grosek

EDR Evasion Fundamentals: Understanding Detection

A defender-first breakdown of EDR detection layers — signatures, behavior, memory — mapped to MITRE ATT&CK TA0005.

Read More
Web Security
Oct 14, 2024 Vid Grosek

Container Security: Breaking Out of Docker

Container isolation breaks under --privileged, mounted Docker sockets, or shared kernel CVEs like Dirty Pipe. I walk through the escape vectors I test in every engagement.

Read More
Web Security
Oct 09, 2024 Vid Grosek

SQL Injection in 2025: Still Dangerous, Still Common

SQLi hides in ORDER BY clauses, ORM raw() calls, and batch imports — not just login forms. Learn the sqlmap techniques and manual methods I rely on in real pen tests.

Read More
Web Security
Oct 04, 2024 Vid Grosek

XSS in Modern Applications: Beyond Basic Payloads

XSS isn't dead in React or Angular — it moved to dangerouslySetInnerHTML, bypassURL, ng-bind-html, and DOM sink abuse. Here's how I find it in modern codebases.

Read More
Web Security
Sep 29, 2024 Vid Grosek

AWS Security Testing: IAM, S3, and Beyond

From wildcard IAM policies and exposed S3 buckets to EC2 metadata SSRF and role chaining — here's what I look for when testing AWS environments.

Read More
Web Security
Sep 24, 2024 Vid Grosek

Azure AD Security: Common Misconfigurations

Consent phishing, legacy auth protocols, guest account over-permissions, and weak Conditional Access policies are the Azure AD misconfigs I find most often in pen tests.

Read More

Explore More

Read my expertise pages, research, or prepare for a pentest.

Expertise About Vid Grosek Research Pentest Preparation

Have Security Questions?

I help companies understand their risks and fix them.

Get in Touch