The Vilkas Wire

Insights and field notes from real-world penetration tests and security research by the experts at Vilkas.

Latest Posts

Showing 21 of 21 total posts

You Passed the Audit. Now Pass the Attack

You Passed the Audit. Now Pass the Attack

Organizations often pass audits but still fall to basic misconfigurations and control gaps. Learn how pentesting provides the real-world…

Nov 18, 20258 min read
Read Post
 Why You Should Secure AD CS Against ESC1 (and How to Do It)

Why You Should Secure AD CS Against ESC1 (and How to Do It)

A misconfigured AD CS template (ESC1) can let any domain user escalate to Domain Admin in minutes. Learn how this common flaw works and the…

Oct 9, 20254 min read
Read Post
Legacy Firewalls, Modern Bootkits: Lessons from the Cisco VPN Zero-Days

Legacy Firewalls, Modern Bootkits: Lessons from the Cisco VPN Zero-Days

Cisco’s zero-day firewall flaws forced global emergency action. Here’s what leaders must know about the growing risk of aging, unsupported…

Sep 30, 20255 min read
Read Post
Active Directory Certificate Services: The Overlooked Weak Link (ESC1, ESC4, ESC8)

Active Directory Certificate Services: The Overlooked Weak Link (ESC1, ESC4, ESC8)

Misconfigured Active Directory Certificate Services (AD CS) can turn a minor foothold into a full domain compromise. Learn the top three…

Sep 25, 20255 min read
Read Post
Why "No Findings" Doesn't Mean No Value in Penetration Testing

Why "No Findings" Doesn't Mean No Value in Penetration Testing

A zero findings report can be useless or a powerful validation of your defenses. Here’s how to make sure it highlights security wins and…

Sep 23, 20255 min read
Read Post
Pentesting in 2025: Beyond the Numbers, Into the Real Risks

Pentesting in 2025: Beyond the Numbers, Into the Real Risks

Description: Pentesting in 2025 isn’t about stats or checklists. It’s about finding the real gaps that attackers still use, before they…

Sep 18, 20253 min read
Read Post

Want to Contribute?

Whether you're breaking down a recent pentest or reflecting on a red team engagement, we welcome your insights. Share your tactics, lessons learned, and perspectives with the community.

Learn How to Contribute