0x00401000:

Steve Nelson

Notes on offensive security, defense, and reverse engineering.


VS Code PowerShell Execution

Using VS Code's Microsoft-signed, trusted PowerShell terminal to run scripts where powershell.exe is locked down by AppLocker, WDAC, or Constrained Language Mode, and how defenders can catch it.

Malicious RBL Credit Card APK

Reverse-engineering a banking trojan disguised as an RBL credit-card app: unpacking two stages of AES-encrypted payloads, defeating string obfuscation, and tracing it back to an exposed Firebase full of stolen data.

ClickFix Defense

Fake reCAPTCHA pages that trick users into pasting an mshta command into the Run dialog. How the ClickFix attack chain works, start to finish, and how to shut it down.