APT
前往频道在 Telegram
This channel discusses: — Offensive Security — RedTeam — Malware Research — OSINT — etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat
显示更多📈 Telegram 频道 APT 的分析概览
频道 APT (@apt_notes) 英语 语言赛道中的 是活跃参与者。目前社区聚集了 16 259 名订阅者,在 技术与应用 类别中位列第 7 759,并在 俄罗斯 地区排名第 40 343 位。
📊 受众指标与增长动态
自 невідомо 创建以来,项目保持高速增长,吸引了 16 259 名订阅者。
根据 31 八月, 2026 的最新数据,频道保持稳定运转。过去 30 天订阅人数变化为 546,过去 24 小时变化为 11,整体触达仍然可观。
- 认证状态: 未认证
- 互动率 (ER): 平均受众互动率为 40.49%。内容发布后 24 小时内通常能获得 18.06% 的反应,占订阅者总量。
- 帖子覆盖: 每篇帖子平均可获得 6 579 次浏览,首日通常累积 2 934 次浏览。
- 互动与反馈: 受众积极参与,单帖平均反应数为 26。
📝 描述与内容策略
作者将该频道定位为表达主观观点的平台:
“This channel discusses:
— Offensive Security
— RedTeam
— Malware Research
— OSINT
— etc
Disclaimer:
t.me/APT_Notes/6
Chat Link:
t.me/APT_Notes_PublicChat”
凭借高频更新(最新数据采集于 01 九月, 2026),频道始终保持新鲜度与高覆盖。分析显示受众积极互动,使其成为 技术与应用 类别中的关键影响点。
16 259
订阅者
+1124 小时
+927 天
+54630 天
帖子存档
16 267
Suspicious Named Pipe Events
https://medium.com/falconforce/falconfriday-suspicious-named-pipe-events-0xff1b-fe475d7ebd8
#windows #pipe #events #blueteam #redteam
16 267
AWS IAM explained for RedTeam & BlueTeam
https://infosecwriteups.com/aws-iam-explained-for-red-and-blue-teams-2dda8b20fbf7
#aws #iam #redteam #blueteam
16 267
Free Labs to Learn Cloud Penetration Testing
http://flaws.cloud/
http://flaws2.cloud/
https://github.com/OWASP/Serverless-Goat
https://n0j.github.io/2017/10/02/aws-s3-ctf.html
https://github.com/torque59/AWS-Vulnerable-Lambda
https://github.com/wickett/lambhack
https://github.com/BishopFox/iam-vulnerable
https://github.com/RhinoSecurityLabs/cloudgoat
https://github.com/appsecco/attacking-cloudgoat2
https://github.com/m6a-UdS/dvca
https://github.com/OWASP/DVSA
https://github.com/nccgroup/sadcloud
#cloud #aws #pentest
16 267
Password Hash Cracking in AWS
https://www.sans.org/blog/password-hash-cracking-amazon-web-services/
#aws #cuda #hashcat
16 267
Bypass EDR with Microsoft Teams
Copy payload into:
%userprofile%\AppData\Local\Microsoft\Teams\current\
Then:
%userprofile%\AppData\Local\Microsoft\Teams\Update.exe --processStart payload.exe --process-start-args "args"
#edr #evasion #teams16 267
Domain Escalation — ShadowCoerce (MS-FSRVP)
Coercing the domain controller machine account to authenticate to a host which is under the control of a threat actor could lead to domain compromise. The most notable technique which involves coerced authentication is the PetitPotam attack which uses the Encrypting File System Remote Protocol (MS-EFSR). However, this is not the only protocol which could be utilized for domain escalation.
Research:
https://pentestlaboratories.com/2022/01/11/shadowcoerce/
PoC:
https://github.com/ShutdownRepo/ShadowCoerce
#ad #escalation #relay #redteam
16 267
Log4jHorizon
A proof of concept for VMWare Horizon instances and allows attackers to execute code as an unauthenticated user using a single HTTP request.
Research:
https://www.sprocketsecurity.com/blog/crossing-the-log4j-horizon-a-vulnerability-with-no-return
Exploit:
https://github.com/puzzlepeaches/Log4jHorizon
#log4j #vmware #horizon #rce
16 267
Important Windows processes for Threat Hunting
https://www.socinvestigation.com/important-windows-processes-for-threat-hunting/
#edr #detection #forensic #process
16 267
Malicious PDF Generator
Generate ten different malicious pdf files with phone-home functionality. Can be used with Burp Collaborator.
https://github.com/pussycat0x/malicious-pdf
#pdf #payload #burp #collaborator
16 267
Deep Technical Analysis of an Office RCE Exploit
https://billdemirkapi.me/unpacking-cve-2021-40444-microsoft-office-rce/
#office #rce #cve_2021_40444
16 267
Domain Domination With Windows Shortcuts
This article on malicious shortcut files and how they can be leveraged to capture NTLM hashes quietly and dominate a network or domain.
https://medium.com/cybersecpadawan/domain-domination-with-windows-shortcuts-6aab1d72b793
#shortcuts #lnk #abuse #windows
16 267
EDR Parallel-asis through Analysis
New method for enumerating Syscalls numbers using the Parallel loader
Research:
https://www.mdsec.co.uk/2022/01/edr-parallel-asis-through-analysis/
C++ Code Snipped:
https://github.com/mdsecactivebreach/ParallelSyscalls
C# Code Snipped:
https://github.com/cube0x0/ParallelSyscalls
#edr #evasion #parallel #csharp
16 267
Optimizing Windows Function Resolving: A Case Study Into GetProcAddress
https://phasetw0.com/windows-internals/optimizing_function_resolving/
#edr #evasion #winapi #getprocaddress
16 267
RemoteNET
This library lets you examine, create and interact with remote objects in other .NET processes.
It's like System.Runtime.Remoting except the other app doesn't need to be compiled (or consent) to support it.
Basically this library lets you mess with objects of any other .NET app without asking for permissions
https://github.com/theXappy/RemoteNET
#csharp #injection #pentest
16 267
Process Injection via KernelCallBackTable
Process injection via the KernelCallBackTable involves replacing original callback function by custom payload so that whenever the function is invoked, payload will be triggered. In this case the fnCOPYDATA callback function has been used.
C# Code Snippet:
https://gist.github.com/sbasu7241/5dd8c278762c6305b4b2009d44d60c13
#edr #evasion #dll #injection #kernelcallbacktable
16 267
Domain Persistence – AdminSDHolder
https://pentestlab.blog/2022/01/04/domain-persistence-adminsdholder/
#ad #adminsdholder #redteam
16 267
An ‘Attack Path’ Mapping Approach to CVEs 2021-42287 and 2021-42278
This post provides Splunk SPL queries for detecting the attacks described in Charlie’s blog, using only Windows Security Log events from a domain controller. Furthermore, this post only examines a subset of the Windows Event logging data source
https://www.trustedsec.com/blog/an-attack-path-mapping-approach-to-cves-2021-42287-and-2021-42278
#ad #pac #s4u2self #research #escalation
16 267
Bypass Defender AV static detection:
If you name a malicious file
*.log Defender doesn't scan it.
UPD:
DumpStack (by any file number) can bypass MDE easily with no detection as mimikatz or eicar mode.
The malicious file can be shown in the console but not identified as malicious.
#defender #evasion #tricks16 267
Phishing With Spoofed Cloud Attachments
This article looks at how you can abuse the cloud attachment feature on O365 to make executables (or any other file types) appear as harmless attachments.
https://mrd0x.com/phishing-o365-spoofed-cloud-attachments/
#phishing #O365 #abuse
16 267
Undetected Azure AD Bruteforce Attack
In late June 2021, Secureworks Counter Threat Unit researchers discovered a flaw in the protocol used by the Azure Active Directory Seamless Single Sign-On feature. This flaw allows threat actors to perform single-factor brute-force attacks against Azure Active Directory (Azure AD) without generating sign-in events in the targeted organization’s tenant.
PoC:
https://github.com/treebuilder/aad-sso-enum-brute-spray
Research:
https://www.secureworks.com/research/undetected-azure-active-directory-brute-force-attacks
#sso #azure #ad #bruteforce #research
