MMCyberLab

Security Assessments (technical)AppSec & DevSecOpsIdentity & Access ManagementCyber DefenseAI Security

Independent cybersecurity research, hands-on labs and unbiased product reviews. Exploring the frontlines of enterprise security so you don't have to.

25+Years in Security
12K+LinkedIn followers
15+Years in Security Leadership

Security researcher
at the cutting edge

Hi, I'm Michal Merta — a cybersecurity professional focused on identity security, zero trust architecture, and AI-driven threats. Through MMCyberLab, I share hands-on research, real-world lab setups, and honest product reviews.

My work bridges the gap between vendor marketing and operational reality — testing security products in realistic environments to give practitioners the insights they actually need.

Security AssessmentsPenetration TestingApplication SecurityIdentity & Access ManagementZero Trust ArchitectureAI SecurityMicrosoft Security StackPrivileged Access ManagementSecurity ArchitectureThreat ModelingCloud SecurityHands-on GEEK

Defender Mindset

Building security from the attacker's perspective to stay ahead of real threats — not just compliance checkboxes.

Hands-on Research

Every review and lab is backed by real testing — no recycled vendor datasheets, no marketing fluff.

Real-World Experience

Insights built from years of incident response, cloud security transformations, Zero Trust programs, and large-scale enterprise environments.

Cloud & AI Security

Exploring modern security challenges across cloud platforms, identity systems, AI workloads, and emerging technologies.

Helping Others

Mentoring security professionals, sharing practical knowledge, and helping build subject-matter expertise through dozens — and sometimes hundreds — of real-world security cases.

Hands-on Security Labs

Practical research environments where I test real-world security scenarios, configurations, and attack paths — no theory without proof.

Active

Identity & Access Management

Deep dives into Entra ID, Active Directory, MFA, Conditional Access, and modern identity architectures for enterprise environments.

Entra IDAD DSSAMLOIDCMFA
Active

Zero Trust Architecture

Implementing never-trust-always-verify principles with the Microsoft security stack, network segmentation, and device compliance policies.

Zero TrustZTNAConditional AccessIntune
Active

AI Security

Exploring LLM security, prompt injection attacks, AI governance frameworks, and securing AI-powered enterprise applications against emerging threats.

LLM SecurityPrompt InjectionAI GovernanceRed Team
Active

Home Lab

Enterprise-grade security at home — physical servers, Proxmox, network segmentation, monitoring stack, and realistic attack simulation.

ProxmoxpfSenseWazuhELK StackVLANs
Active

Microsoft Security

Hands-on with Defender XDR, Microsoft Sentinel, Defender for Identity, and the full Microsoft security ecosystem in real attack scenarios.

SentinelDefender XDRDefender for IdentityKQL
Coming Soon

Privileged Access

PAM solutions, tiered administration models, just-in-time access, and protecting the most sensitive accounts in the organization.

PAMPIMJIT AccessTiered Model

Unbiased Product Reviews

Real-world testing of security products — not sponsored content, just honest assessments from hands-on experience.

PB

Passbolt

Password Management

Open-source, self-hosted password manager with excellent team sharing and a GPG-based trust model. Ideal for security-conscious teams wanting full control over their credential vault.

Solid for Teams

KE

Keeper

Enterprise Password Management

Feature-rich enterprise password manager with strong compliance reporting and polished admin controls. Keeper Secrets Manager adds solid CI/CD secret injection capabilities.

Enterprise Ready

KW

Kiteworks

Secure File Sharing

Specialized secure content collaboration platform excelling in highly regulated industries. ITAR, CMMC, and FedRAMP compliance built-in with granular audit trails and DRM controls.

Compliance Champion

Technical Deep Dives

In-depth articles on cybersecurity architecture, hands-on lab findings, and lessons learned from real-world security testing.

Coming Soon
Q4 2025

Building a Zero Trust Home Lab with Microsoft Entra ID

Step-by-step guide to implementing enterprise-grade zero trust in a home lab using Entra ID, Intune, and Conditional Access policies with real traffic.

Zero TrustEntra IDHome Lab
Coming Soon
Q4 2025

Prompt Injection in Enterprise LLM Applications

An exploration of prompt injection attack vectors in enterprise AI deployments, with practical detection strategies and mitigation patterns for production systems.

AI SecurityLLMsRed Team
Coming Soon
Q1 2026

Defender for Identity vs Sentinel: When to Use Which

Clarifying the overlap, synergies, and gaps between Microsoft Defender for Identity and Microsoft Sentinel across hybrid Active Directory environments.

Microsoft SecuritySentinelDefender

Get notified when articles publish

More in-depth articles in progress. Drop your email to be notified.

Let's Connect

Have a question, collaboration idea, or want to discuss cybersecurity? Reach out through any of these channels.