Areas of Expertise
The areas where I focus and where most companies fail.
These are the core penetration testing areas Vid Grosek covers - Slovenia's first OSCE3 and OSCP+ certified penetration tester, with 18+ years of experience, delivering engagements through Telprom d.o.o.
Active Directory
Attacks I see in 90% of Slovenian companies. From regular user to Domain Admin.
Web Security
Modern testing beyond OWASP Top 10. Logic flaws, authentication vulnerabilities.
API Security
Why Swagger is your worst enemy. JWT, OAuth, SSO failures.
Cloud Security
Cloud misconfigurations I exploit the most. IAM, privilege escalation.
Red Team
Red Team vs Pentest vs Audit. What a comprehensive attack simulation really means.
Evasion & EDR
Why EDR didn't stop me. Command-line obfuscation, detection blind spots.
Reporting & Risk
CVSS is not risk. How I score vulnerabilities for real decision-makers.
More Content
Read my articles, research, or prepare for a pentest.
Frequently Asked Questions
What does a penetration test cover?
A penetration test covers Active Directory, web application, API and cloud security, red team operations and EDR/AV evasion, finishing with reporting and risk assessment based on real business impact.
Red team vs pentest vs audit - what is the difference?
A penetration test finds and exploits as many vulnerabilities as possible within an agreed scope, while a red team operation simulates a real attacker with a defined objective and tests detection and response. An audit compares your state against security standards without actively exploiting vulnerabilities.
Where do you provide penetration testing?
Penetration testing is delivered by Vid Grosek through Telprom d.o.o., based in Ljubljana, for clients in Slovenia and across the European Union.