Skip to main content

Research, field notes, and practitioner perspective

The Vilkas Wire

Insights and field notes from real-world penetration tests and security research by the experts at Vilkas.

Latest Posts

Showing 28 of 28 total posts

SMB Signing Not Enforced: Real-World Active Directory Attack Chains Explained

SMB Signing Not Enforced: Real-World Active Directory Attack Chains Explained

How unsigned SMB traffic is abused during internal penetration tests, why “enabled but not required” still fails, and how this…

Jan 20, 20267 min read
Read Post
When Active Directory Is in Scope, Don’t Handcuff the Pentest

When Active Directory Is in Scope, Don’t Handcuff the Pentest

When Active Directory is in scope, giving your pentester a low‑privilege password is not cheating; it simulates a compromised user account…

Jan 6, 20267 min read
Read Post
You Passed the Audit. Now Pass the Attack

You Passed the Audit. Now Pass the Attack

Organizations often pass audits but still fall to basic misconfigurations and control gaps. Learn how pentesting provides the real-world…

Nov 18, 20258 min read
Read Post

For practitioners who want to share useful work

Want to Contribute?

Whether you're breaking down a recent pentest or reflecting on a red team engagement, we welcome your insights. Share your tactics, lessons learned, and perspectives with the community.

Learn How to Contribute