Vedran Dojčinović

Hi, I'm Vedran

Security practitioner working across detection engineering, Active Directory security, and offensive security — I build detections, then attack the environment to see whether they hold up.

This is where I publish research write-ups, detection rules, and the lessons that come out of hands-on lab work: building environments, breaking them, and figuring out what a defender would actually see.

2 posts1 ATT&CK technique1 detection rule

What I write about

  1. Detection Engineering

    Writing and tuning detections — Wazuh rules, Sigma, and the baseline work that decides whether they actually fire.

  2. Active Directory Security

    Kerberos, delegation, certificate services, and the attack paths that quietly turn one account into domain-wide access.

  3. Offensive Security

    Building labs, breaking them, and mapping what a defender would actually see when the attack runs.

Latest posts

All posts →