Skip to main content

Research, field notes, and practitioner perspective

The Vilkas Wire

Insights and field notes from real-world penetration tests and security research by the experts at Vilkas.

Latest Posts

Showing 31 of 31 total posts

When Active Directory Is in Scope, Don’t Handcuff the Pentest

When Active Directory Is in Scope, Don’t Handcuff the Pentest

When Active Directory is in scope, giving your pentester a low‑privilege password is not cheating; it simulates a compromised user account…

Jan 6, 20267 min read
Read Post
GRC vs. pentest

You Passed the Audit. Now Pass the Attack

Organizations often pass audits but still fall to basic misconfigurations and control gaps. Learn how pentesting provides the real-world…

Nov 18, 20258 min read
Read Post
 Why You Should Secure AD CS Against ESC1 (and How to Do It)

Why You Should Secure AD CS Against ESC1 (and How to Do It)

A misconfigured AD CS template (ESC1) allows a domain user escalate to Domain Admin in minutes. Learn about this common flaw and the simple…

Oct 9, 20254 min read
Read Post
Abstract of VPN hack

Legacy Firewalls, Modern Bootkits: Lessons from the Cisco VPN Zero-Days

Cisco’s zero-day firewall flaws forced global emergency action. Here’s what leaders must know about the growing risk of aging, unsupported…

Sep 30, 20255 min read
Read Post
Zero Findings neat data center

Why "No Findings" Doesn't Mean No Value in Penetration Testing

A zero findings report can be useless or a powerful validation of your defenses. Here’s how to make sure it highlights security wins and…

Sep 23, 20255 min read
Read Post

For practitioners who want to share useful work

Want to Contribute?

Whether you're breaking down a recent pentest or reflecting on a red team engagement, we welcome your insights. Share your tactics, lessons learned, and perspectives with the community.

Learn How to Contribute