About
Diese Seite ist auch auf Deutsch verfügbar.
VidraSec was founded in 2024 by me, Martin Grottenthaler.
I have worked full-time in IT security consulting since 2017. My focus is on Windows, Active Directory and Entra ID security, as well as the security of internal systems.
Every VidraSec engagement is run by me personally: I scope the work, test your systems, write the report, and lead the debrief. There are no account managers, delivery teams, or junior substitutions. If you want to understand why I built VidraSec around that single-operator model, the comparison Boutique single-operator pentest vs. large firm vs. PTaaS lays out the trade-offs.
You can find my full CV on my LinkedIn (opens in a new tab) page, and my verified credentials on Credly (opens in a new tab).
Certifications
(opens in a new tab)
(opens in a new tab)
(opens in a new tab)
(opens in a new tab)
- OSCP: Offensive Security Certified Professional (each badge above links to its public Credly record)
- CISSP: Certified Information Systems Security Professional
- GCFA: GIAC Certified Forensic Analyst
- GWAPT: GIAC Web Application Penetration Tester
Talks at conferences
I have presented original Windows and Active Directory security research at international conferences, including Troopers (Heidelberg), Hacktivity (Budapest), and IT-SECX (St. Pölten). That speaking experience feeds directly back into clear, accurate reporting and debriefs.
Troopers 2023: The Power of Coercion Techniques in Windows Environments
The original talk at Troopers 2023 (opens in a new tab), one of Europe’s most respected enterprise security conferences.
IT-SECX 2021: Utilman is back (German)
Hacktivity 2023: The Power of Coercion Techniques in Windows Environments
Another (later) version of the talk I did at Troopers. It is a little bit shorter, but being the third time I’ve done the talk, it might be better. I will let you decide.
Teaching
I also teach a hands-on Udemy course, Windows 11 Client Hacking (opens in a new tab), which walks through attacking and hardening modern Windows clients. The same offensive techniques inform how I test client environments during engagements.
The name VidraSec
“Sec” stands for security. “Vidra” is the Slavic word for otter 🦦 (opens in a new tab), chosen because it sounds nice and was still available.
The otter connection to security: in medieval Austria, the Catholic Church banned meat during fasting but allowed fish. People classified otters as fish to get around the restriction, making otters part of one of history’s earliest documented life hacks. Unfortunately, this wasn’t great for the otters (or their beaver 🦫 friends), but they are protected now.