ClickFix Defense

Fake reCAPTCHA pages that trick users into pasting an mshta command into the Run dialog. How the ClickFix attack chain works, start to finish, and how to shut it down.

Malicious RBL Credit Card APK

Reverse-engineering a banking trojan disguised as an RBL credit-card app: unpacking two stages of AES-encrypted payloads, defeating string obfuscation, and tracing it back to an exposed Firebase full of stolen data.

VS Code PowerShell Execution

Using VS Code's Microsoft-signed, trusted PowerShell terminal to run scripts where powershell.exe is locked down by AppLocker, WDAC, or Constrained Language Mode, and how defenders can catch it.

Red Team Resources

Reference guide for red team tools, techniques, and procedures organized by MITRE ATT&CK phases.

CDN Phishing Walkthrough

A walkthrough on setting up Azure CDN phishing infrastructure using EvilGoPhish for authorized red team engagements.

Security Safety Tips

A practical guide covering data removal, password security, public area safety, and home security best practices.

Warhorse Configuration File

An example Warhorse phishing configuration file for automating red team infrastructure deployment.