en
Feedback
APT

APT

Open in Telegram

This channel discusses: — Offensive Security — RedTeam — Malware Research — OSINT — etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat

Show more

📈 Analytical overview of Telegram channel APT

Channel APT (@apt_notes) in the English language segment is an active participant. Currently, the community unites 14 829 subscribers, ranking 8 765 in the Technologies & Applications category and 44 988 in the Russia region.

📊 Audience metrics and dynamics

Since its creation on невідомо, the project has demonstrated rapid growth, gathering an audience of 14 829 subscribers.

According to the latest data from 22 June, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by 460 over the last 30 days and by 20 over the last 24 hours, overall reach remains high.

  • Verification status: Not verified
  • Engagement rate (ER): The average audience engagement rate is 60.16%. Within the first 24 hours after publication, content typically collects N/A% reactions from the total number of subscribers.
  • Post reach: On average, each post receives 8 918 views. Within the first day, a publication typically gains 0 views.
  • Reactions and interaction: The audience actively supports content: the average number of reactions per post is 20.

📝 Description and content policy

The author describes the resource as a platform for expressing subjective opinions:
This channel discusses: — Offensive Security — RedTeam — Malware Research — OSINT — etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat

Thanks to the high frequency of updates (latest data received on 23 June, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.

14 829
Subscribers
+2024 hours
+987 days
+46030 days
Posts Archive
APT
14 829
Early Bird Catches the Wormhole: Observations from the StellarParticle Campaign StellarParticle, an adversary campaign associ
Early Bird Catches the Wormhole: Observations from the StellarParticle Campaign StellarParticle, an adversary campaign associated with COZY BEAR, was active throughout 2021 leveraging novel tactics and techniques in supply chain attacks observed by CrowdStrike incident responders https://www.crowdstrike.com/blog/observations-from-the-stellarparticle-campaign/ #threatintel #dfir #blueteam #malware

APT
14 829
Windows Win32k — Local Privilege Escalation (CVE-2022-21882) https://github.com/KaLendsi/CVE-2022-21882 #windows #lpe #cve

APT
14 829
FunctionStomping This is a brand-new technique for shellcode injection to evade AVs and EDRs. This technique is inspired by M
FunctionStomping This is a brand-new technique for shellcode injection to evade AVs and EDRs. This technique is inspired by Module Stomping and has some similarities.The big advantage of this technique is that it isn't overwritting an entire module or PE, just one function and the target process can still use any other function from the target module. https://github.com/Idov31/FunctionStomping #edr #evasion #stomping #maldev #cpp

APT
14 829
SMBeagle This is fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be re
SMBeagle This is fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. https://github.com/punk-security/SMBeagle #ad #share #enum #tools

APT
14 829
List of Vulnerable Functions for Different Languages This list contains signatures for potentially vulnerable functions for numerous languages in a format suitable for use. https://rules.sonarsource.com/ https://github.com/wireghoul/graudit #appsec #vulnerable #function #source

APT
14 829
Cobalt Strike, a Defender’s Guide In this research, exposes adversarial Tactics, Techniques and Procedures (TTPs) as well as
Cobalt Strike, a Defender’s Guide In this research, exposes adversarial Tactics, Techniques and Procedures (TTPs) as well as the tools use to execute mission objectives. In most of cases, the threat actors utilizing Cobalt Strike. Therefore, defenders should know how to detect Cobalt Strike in various stages of its execution. The primary purpose of this articles is to expose the most common techniques from the intrusions track and provide detections. Having said that, not all of Cobalt Strike’s features will be discussed. # https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/ # https://thedfirreport.com/2022/01/24/cobalt-strike-a-defenders-guide-part-2/ #cobaltstrike #research #blueteam

APT
14 829
PwnKit: Local Privilege Escalation Vulnerability in Polkit’s Pkexec (CVE-2021-4034) The Qualys Research Team has discovered a
PwnKit: Local Privilege Escalation Vulnerability in Polkit’s Pkexec (CVE-2021-4034) The Qualys Research Team has discovered a memory corruption vulnerability in polkit’s pkexec, a SUID-root program that is installed by default on every major Linux distribution. This easily exploited vulnerability allows any unprivileged user to gain full root privileges on a vulnerable host by exploiting this vulnerability in its default configuration. Research: https://blog.qualys.com/vulnerabilities-threat-research/2022/01/25/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034 PoC: https://github.com/arthepsy/CVE-2021-4034 Exploit: https://github.com/berdav/CVE-2021-4034 #linux #lpe #polkit #cve

APT
14 829
Linux Root PrivEsc and Escaping Containers (CVE-2022-0185) Research: https://www.willsroot.io/2022/01/cve-2022-0185.html Exploit: https://github.com/Crusaders-of-Rust/CVE-2022-0185 #linux #kernel #lpe #escape #container #0day

APT
14 829
SonicWall SMA-100 Unauth RCE Bad Blood is an exploit for CVE-2021-20038, a stack-based buffer overflow in the httpd binary of SMA-100 series systems using firmware versions 10.2.1.x. The exploit, as written, will open up a telnet bind shell on port 1270. An attacker that connects to the shell will achieve execution as nobody. Research: https://attackerkb.com/topics/QyXRC1wbvC/cve-2021-20038/rapid7-analysis Exploit: https://github.com/jbaines-r7/badblood #sonicwall #exploit #rce #cve

APT
14 829
RefleXXion RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypas
RefleXXion RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first collects the syscall numbers of the NtOpenFile, NtCreateSection, NtOpenSection and NtMapViewOfSection found in the LdrpThunkSignature array. https://github.com/hlldz/RefleXXion #edr #evasion #cpp #redteam

APT
14 829
Create a Hidden Account in Windows A tool for creating hidden accounts using the registry. In addition to adding hidden accou
Create a Hidden Account in Windows A tool for creating hidden accounts using the registry. In addition to adding hidden accounts, the tool also adds functions to check hidden accounts and delete hidden accounts, so that both the red team and the blue team can use this tool. https://github.com/wgpsec/CreateHiddenAccount #ad #windows #hidden #account

APT
14 829
CRLF OneLiner A simple Bash one liner with aim to automate CRLF vulnerability scanning. This is an extremely helpful and practical One liner for Bug Hunters, which helps you find CRLF missconfiguration in every possible method. Simply replace the links in subdomains.txt with the URL you want to target. This will help you scan for CRLF vulnerability without the need of an external tool. What you have to do is to copy-and-paste the commands into your terminal and finger crossed for any possible CRLF. Bash OneLiner: input='CRLF-one-liner/subdomains.txt';while IFS= read -r targets; do cat CRLF-one-liner/crlf_payloads.txt |xargs -I % sh -c "curl -vs --max-time 9 $targets/% 2>&1 |grep -q '< Set-Cookie: ?crlf'&& echo $targets '[+] is vulnerable with payload: '%>>crlf_results.txt||echo '[-] Not vulnerable: '$targets";done<$input crlf_payloads.txt: https://raw.githubusercontent.com/kleiton0x00/CRLF-one-liner/master/crlf_payloads.txt #crlf #bash #oneliner #bugbounty

APT
14 829
Log4j — WAF and Patches Bypass Tricks https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words #log4j #waf #bypass #bugbounty

APT
14 829
Anti-Spam Bypass A script that helps you understand why your E-Mail ended up in Spam https://github.com/mgeeky/decode-spam-he
Anti-Spam Bypass A script that helps you understand why your E-Mail ended up in Spam https://github.com/mgeeky/decode-spam-headers #phishing #anispam #bypass

APT
14 829
Custom Previews For Malicious Attachments A phishing technique that allows attackers to create fake previews for their malici
Custom Previews For Malicious Attachments A phishing technique that allows attackers to create fake previews for their malicious attachment with Google Mail. https://mrd0x.com/phishing-google-users-by-spoofing-previews/ #phishing #gmail #attachments

APT
14 829
Finding Sensitive Files for BugBounty /proc/self/cwd/index.php /proc/self/cwd/main.py /etc/motd /proc/net/udp /proc/net/arp /proc/self/environ /var/run/secrets/kubernetes.io/serviceaccount /proc/cmdline /proc/mounts /etc/motd /etc/mysql/my.cnf /proc/sched_debug /home/ user/.bash_history /home/user/.ssh/id_rsa #sensitive #files #bugbounty #bugbountytips

APT
14 829
aesKrbKeyGen Script to calculate Active Directory Kerberos keys (AES256 and AES128) for an account, using its plaintext password. Either of the resulting keys can be utilized with Impacket's getTGT.py to obtain a TGT for the account, provided it is configured to support AES encryption. https://github.com/Tw1sm/AesKrbKeyGen #ad #kerbeos #tgt #tools

APT
14 829
Process Ghosting This article describes a new executable image tampering attack similar to, but distinct from, Doppelgänging
Process Ghosting This article describes a new executable image tampering attack similar to, but distinct from, Doppelgänging and Herpaderping. With this technique, an attacker can write a piece of malware to disk in such a way that it’s difficult to scan or delete it — and where it then executes the deleted malware as though it were a regular file on disk. This technique does not involve code injection, process hollowing, or Transactional NTFS (TxF). Research: https://www.elastic.co/blog/process-ghosting-a-new-executable-image-tampering-attack C# Code Snippet: https://github.com/Wra7h/SharpGhosting #edr #evasion #process #ghosting #csharp

APT
14 829
Adding DCSync Permissions from Linux https://www.n00py.io/2022/01/adding-dcsync-permissions-from-linux/ #ad #dcsync #linux

APT
14 829
LDAP Relay Scan A tool to check Domain Controllers for LDAP server protections regarding the relay of NTLM authentication. https://github.com/zyn3rgy/LdapRelayScan #ad #ldap #scan #tools