Security Blog & Insights
Written by Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester, based in Ljubljana.
Opinions, analysis, and insights from real engagements. No vendor fluff.
All Posts
Why I Get Domain Admin in Every Penetration Test
EDR and firewalls don't fix misconfigurations. I walk through my standard 4-hour path from network plug-in to Domain Admin — and what blocks it.
Read MoreThe Active Directory Security Mistakes I See in Every Slovenian Company
After 50+ penetration tests in Slovenia, these recurring AD misconfigurations hand me Domain Admin access — almost every single time.
Read MoreBuilding a Security Culture That Actually Works
Technical controls fail when employees hide phishing clicks out of fear. Here is how to build security awareness that people actually follow.
Read MoreWhy Hackers Choose Their Targets (It Might Be You)
"We are not a target" is the most dangerous assumption in cybersecurity. I explain how opportunistic and targeted attackers actually select their victims.
Read MoreAssessing Your Security Maturity: Where Do You Stand?
Investing in red teams before deploying endpoint detection wastes budget. This practical maturity model tells you what each level needs and what to tackle next.
Read MoreVulnerability vs Risk: What Decision Makers Need to Know
Thousands of scanner findings do not equal thousands of risks. Learn the Risk = Likelihood x Impact framework that turns CVE lists into actionable priorities.
Read MoreHow to Buy Security Testing: A Guide for Decision Makers
Not all pentests deliver equal value. I show decision-makers exactly how to vet vendors, read sample reports, and avoid paying for glorified automated scans.
Read MoreHow Attackers Think: The Mindset Behind Breaches
APT groups spend weeks in quiet reconnaissance before striking. Understanding attacker patience and creativity is the first step toward stronger defense.
Read MoreRed Team vs Penetration Test: Which Do You Need?
A penetration test maximizes vulnerability coverage; a red team simulates a real adversary. Here is how to choose the right one for your organization.
Read MoreWhat Penetration Testers Actually Do (And Why It Matters)
From scoping and OSINT to Active Directory exploitation and remediation — a methodical look at what a real pentest actually involves.
Read MoreExplore More
Read my expertise pages, research, or prepare for a pentest.