Skip to main content

Research, field notes, and practitioner perspective

The Vilkas Wire

Insights and field notes from real-world penetration tests and security research by the experts at Vilkas.

Latest Posts

Showing 30 of 30 total posts

AD Continuous Monitoring

What Happens to Active Directory Between Annual Penetration Tests

Active Directory changes constantly between annual penetration tests, creating hidden security drift, access creep, and opening up new…

May 18, 20268 min read
Read Post
Risk of Not Enforcing SMB Signing

SMB Signing Not Enforced: Real-World Active Directory Attack Chains Explained

How unsigned SMB traffic is abused during internal penetration tests, why “enabled but not required” still fails, and how this…

Jan 20, 20267 min read
Read Post
When Active Directory Is in Scope, Don’t Handcuff the Pentest

When Active Directory Is in Scope, Don’t Handcuff the Pentest

When Active Directory is in scope, giving your pentester a low‑privilege password is not cheating; it simulates a compromised user account…

Jan 6, 20267 min read
Read Post

For practitioners who want to share useful work

Want to Contribute?

Whether you're breaking down a recent pentest or reflecting on a red team engagement, we welcome your insights. Share your tactics, lessons learned, and perspectives with the community.

Learn How to Contribute