Security Blog & Insights
Written by Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester, based in Ljubljana.
Opinions, analysis, and insights from real engagements. No vendor fluff.
All Posts
AMSI Bypass Techniques: PowerShell and Beyond
How Microsoft's Antimalware Scan Interface works across script engines — and which log events reveal attacker bypass attempts.
Read MoreEDR Evasion Fundamentals: Understanding Detection
A defender-first breakdown of EDR detection layers — signatures, behavior, memory — mapped to MITRE ATT&CK TA0005.
Read MoreContainer Security: Breaking Out of Docker
Container isolation breaks under --privileged, mounted Docker sockets, or shared kernel CVEs like Dirty Pipe. I walk through the escape vectors I test in every engagement.
Read MoreSQL Injection in 2025: Still Dangerous, Still Common
SQLi hides in ORDER BY clauses, ORM raw() calls, and batch imports — not just login forms. Learn the sqlmap techniques and manual methods I rely on in real pen tests.
Read MoreXSS in Modern Applications: Beyond Basic Payloads
XSS isn't dead in React or Angular — it moved to dangerouslySetInnerHTML, bypassURL, ng-bind-html, and DOM sink abuse. Here's how I find it in modern codebases.
Read MoreAWS Security Testing: IAM, S3, and Beyond
From wildcard IAM policies and exposed S3 buckets to EC2 metadata SSRF and role chaining — here's what I look for when testing AWS environments.
Read MoreAzure AD Security: Common Misconfigurations
Consent phishing, legacy auth protocols, guest account over-permissions, and weak Conditional Access policies are the Azure AD misconfigs I find most often in pen tests.
Read MoreGraphQL Security: Beyond REST Vulnerabilities
GraphQL's single endpoint and introspection feature create unique risks — batching abuse, IDOR through aliases, and schema enumeration need dedicated testing methodology.
Read MoreJWT Security: Common Mistakes and How to Exploit Them
Algorithm confusion, none-bypass, weak HMAC secrets, and key injection attacks make JWT one of the most exploitable auth mechanisms I test. Here's the full breakdown.
Read MoreSSRF Attacks: Making Servers Attack Themselves
Server-Side Request Forgery hits differently in cloud-native stacks — IMDS credential theft, internal port scanning, and blind SSRF via DNS callbacks explained.
Read MoreExplore More
Read my expertise pages, research, or prepare for a pentest.