en
Feedback
APT

APT

Open in Telegram

This channel discusses: β€” Offensive Security β€” RedTeam β€” Malware Research β€” OSINT β€” etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat

Show more

πŸ“ˆ Analytical overview of Telegram channel APT

Channel APT (@apt_notes) in the English language segment is an active participant. Currently, the community unites 16 299 subscribers, ranking 7 749 in the Technologies & Applications category and 40 394 in the Russia region.

πŸ“Š Audience metrics and dynamics

Since its creation on Π½Π΅Π²Ρ–Π΄ΠΎΠΌΠΎ, the project has demonstrated rapid growth, gathering an audience of 16 299 subscribers.

According to the latest data from 03 September, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by 546 over the last 30 days and by 26 over the last 24 hours, overall reach remains high.

  • Verification status: Not verified
  • Engagement rate (ER): The average audience engagement rate is 54.39%. Within the first 24 hours after publication, content typically collects 13.17% reactions from the total number of subscribers.
  • Post reach: On average, each post receives 8 865 views. Within the first day, a publication typically gains 2 146 views.
  • Reactions and interaction: The audience actively supports content: the average number of reactions per post is 13.

πŸ“ Description and content policy

The author describes the resource as a platform for expressing subjective opinions:
β€œThis channel discusses: β€” Offensive Security β€” RedTeam β€” Malware Research β€” OSINT β€” etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat”

Thanks to the high frequency of updates (latest data received on 04 September, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.

16 299
Subscribers
+2624 hours
+917 days
+54630 days
Posts Archive
APT
16 310
Вакансия Компания Angara Security (https://www.angarasecurity.ru/) (Π“Πš Ангара) Π² ΠΎΡ‚Π΄Π΅Π» Π°Π½Π°Π»ΠΈΠ·Π° защищСнности ΠΈΡ‰Π΅Ρ‚ экспСрта ΠΏΠΎ Π°Π½Π°Π»ΠΈΠ·Ρƒ защищСнности ΠΏΡ€ΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΠΉ. Π§Π΅ΠΌ прСдстоит Π·Π°Π½ΠΈΠΌΠ°Ρ‚ΡŒΡΡ: ОсновноС: β€” ΠΏΡ€ΠΎΠ²Π΅Π΄Π΅Π½ΠΈΠ΅ Π°Π½Π°Π»ΠΈΠ·Π° защищСнности ΠΈ тСстирования Π½Π° ΠΏΡ€ΠΎΠ½ΠΈΠΊΠ½ΠΎΠ²Π΅Π½ΠΈΠ΅ Π²Π΅Π± ΠΈ/ΠΈΠ»ΠΈ ΠΌΠΎΠ±ΠΈΠ»ΡŒΠ½Ρ‹Ρ… ΠΏΡ€ΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΠΉ (Π³Π΄Π΅ скилла ΠΈ Π·Π°Π΄ΠΎΡ€Π° большС Ρ…Π²Π°Ρ‚ΠΈΡ‚) β€” ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠ°Π½ΠΈΠ΅ Π² Π°ΠΊΡ‚ΡƒΠ°Π»ΡŒΠ½ΠΎΠΌ состоянии ΡΡƒΡ‰Π΅ΡΡ‚Π²ΡƒΡŽΡ‰Π΅ΠΉ Π±Π°Π·Ρ‹ Π·Π½Π°Π½ΠΈΠΉ ΠΏΠΎ Π½Π°ΠΏΡ€Π°Π²Π»Π΅Π½ΠΈΡŽ Π°Π½Π°Π»ΠΈΠ·Π° защищСнности ΠΏΡ€ΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΠΉ β€” ΡƒΠ»ΡƒΡ‡ΡˆΠ΅Π½ΠΈΠ΅ качСства выполнСния Π²Ρ‹ΡˆΠ΅ΡƒΠΊΠ°Π·Π°Π½Ρ‹Ρ… Ρ€Π°Π±ΠΎΡ‚ β€” участиС Π² Red Team ΠΏΡ€ΠΎΠ΅ΠΊΡ‚Π°Ρ… Помимо (Ссли Π±ΡƒΠ΄Π΅Ρ‚ ΠΆΠ΅Π»Π°Π½ΠΈΠ΅ ΠΈ Π²ΠΎΠ·ΠΌΠΎΠΆΠ½ΠΎΡΡ‚ΡŒ): β€” ΠΏΡ€ΠΎΠ²Π΅Π΄Π΅Π½ΠΈΠ΅ инфраструктурных тСстирований Π½Π° ΠΏΡ€ΠΎΠ½ΠΈΠΊΠ½ΠΎΠ²Π΅Π½ΠΈΠ΅ (внСшка/внутряк) β€” тСстированиС с ΠΏΡ€ΠΈΠΌΠ΅Π½Π΅Π½ΠΈΠ΅ΠΌ ΠΌΠ΅Ρ‚ΠΎΠ΄ΠΎΠ² ΡΠΎΡ†ΠΈΠ°Π»ΡŒΠ½ΠΎΠΉ ΠΈΠ½ΠΆΠ΅Π½Π΅Ρ€ΠΈΠΈ β€” ΠΈΠ½Ρ‹Π΅ активности, связанныС с пСнтСстом ΠΈ Π°Π½Π°Π»ΠΈΠ·ΠΎΠΌ защищСнности Π§Π΅Π³ΠΎ ΠΎΠΆΠΈΠ΄Π°Π΅ΠΌ ΠΎΡ‚ ΠΊΠ°Π½Π΄ΠΈΠ΄Π°Ρ‚Π°: β€” Π½Π°Π»ΠΈΡ‡ΠΈΠ΅ ΠΎΠ±Ρ‰Π΅ΠΉ Π˜Π‘-шной Π±Π°Π·Ρ‹ ΠΏΠΎ ΠΎΠΏΠ΅Ρ€Π°Ρ†ΠΈΠΎΠ½Π½Ρ‹ΠΌ систСмам, ΠΊΠΎΠΌΠΏΡŒΡŽΡ‚Π΅Ρ€Π½Ρ‹ΠΌ сСтям, Π²Π΅Π±-тСхнологиям, ΠΏΡ€ΠΎΠ³Ρ€Π°ΠΌΠΌΠΈΡ€ΠΎΠ²Π°Π½ΠΈΡŽ, ΠΊΡ€ΠΈΠΏΡ‚ΠΎΠ³Ρ€Π°Ρ„ΠΈΠΈ β€” Π°Π΄Π΅ΠΊΠ²Π°Ρ‚Π½ΠΎΠ΅ ΠΏΠΎΠ½ΠΈΠΌΠ°Π½ΠΈΠ΅ Ρ‚ΠΈΠΏΠΎΠ²Ρ‹Ρ… уязвимостСй ΠΈ Π°Ρ‚Π°ΠΊ Π½Π° прилоТСния (хотя Π±Ρ‹ ΠΈΠ· списка OWASP Π½Π° ΡƒΡ€ΠΎΠ²Π½Π΅ "ΠΌΠΎΠ³Ρƒ ΠΎΠ±ΡŠΡΡΠ½ΠΈΡ‚ΡŒ ΠΊΠ°ΠΊ Ρ€Π°Π±ΠΎΡ‚Π°Π΅Ρ‚ ΠΏΠΎΠ΄ ΠΊΠ°ΠΏΠΎΡ‚ΠΎΠΌ ΠΈ ΠΏΠΎΠΊΠ°Π·Π°Ρ‚ΡŒ ΠΏΡ€ΠΈΠΌΠ΅Ρ€ эксплуатации Π½Π° ΠΏΡ€Π°ΠΊΡ‚ΠΈΠΊΠ΅") β€” Ρ…ΠΎΡ€ΠΎΡˆΠ΅Π΅ ΠΏΠΎΠ½ΠΈΠΌΠ°Π½ΠΈΠ΅ ΠΎΠ±Ρ‰Π΅ΠΉ ΠΌΠ΅Ρ‚ΠΎΠ΄ΠΎΠ»ΠΎΠ³ΠΈΠΈ тСстирования Π½Π° ΠΏΡ€ΠΎΠ½ΠΈΠΊΠ½ΠΎΠ²Π΅Π½ΠΈΠ΅ (ΠΊΠ°ΠΊΠΎΠΉ этап Π·Π° ΠΊΠ°ΠΊΠΈΠΌ ΠΈΠ΄Π΅Ρ‚, ΠΊΠ°ΠΊΠΈΠ΅ дСйствия Π½Π° ΠΊΠ°ΠΆΠ΄ΠΎΠΌ этапС Π½ΡƒΠΆΠ½ΠΎ Π²Ρ‹ΠΏΠΎΠ»Π½ΡΡ‚ΡŒ, ΠΊΠ°ΠΊΠΈΠΌΠΈ инструмСнтами) β€” ΡƒΠ²Π΅Ρ€Π΅Π½Π½ΠΎΠ΅ Π²Π»Π°Π΄Π΅Π½ΠΈΠ΅ Ρ‚ΠΈΠΏΠΎΠ²Ρ‹ΠΌ инструмСнтариСм пСнтСстСра Π§Ρ‚ΠΎ ΠΌΡ‹ Π³ΠΎΡ‚ΠΎΠ²Ρ‹ ΠΏΡ€Π΅Π΄Π»ΠΎΠΆΠΈΡ‚ΡŒ: β€” ΠΊΠΎΠ½ΠΊΡƒΡ€Π΅Π½Ρ‚ΠΎΡΠΏΠΎΡΠΎΠ±Π½ΡƒΡŽ Π—ΠŸ с Π³ΠΎΠ΄ΠΎΠ²Ρ‹ΠΌΠΈ прСмиями β€” Ρ€Π°Π·Π½ΠΎΠΎΠ±Ρ€Π°Π·ΠΈΠ΅ ΠΏΡ€ΠΎΠ΅ΠΊΡ‚ΠΎΠ² ΠΈ ΠΊΠ»ΠΈΠ΅Π½Ρ‚ΠΎΠ² (ΠΎΡ‚ Ρ€Π°Π·ΠΎΠ²Ρ‹Ρ… тСстирований Π΄ΠΎ Π³ΠΎΠ΄ΠΎΠ²Ρ‹Ρ… ΠΏΡ€ΠΎΠ΅ΠΊΡ‚ΠΎΠ² с большим интСрСсным скоупом) β€” Π³ΠΈΠ±Ρ€ΠΈΠ΄Π½Ρ‹ΠΉ Ρ„ΠΎΡ€ΠΌΠ°Ρ‚ Ρ€Π°Π±ΠΎΡ‚Ρ‹ ΡƒΠ΄Π°Π»Π΅Π½ΠΊΠ°/офис (ΠΏΠΎΠ»Π½ΠΎΠΉ ΡƒΠ΄Π°Π»Π΅Π½ΠΊΠΈ Π½Π΅Ρ‚) β€” Π”ΠœΠ‘ со стоматологиСй β€” ΠΏΡ€ΠΎΡ„ΠΈΠ»ΡŒΠ½Ρ‹Π΅ сСртификации ΠΈ ΠΊΠΎΠ½Ρ„Π΅Ρ€Π΅Π½Ρ†ΠΈΠΈ Π·Π° счСт работодатСля β€” Π²Π½ΡƒΡ‚Ρ€Π΅Π½Π½ΠΈΠ΅ рСлакс-мСроприятия Π² Ρ€Π°ΠΌΠΊΠ°Ρ… офиса Π£Π·Π½Π°Ρ‚ΡŒ подробности ΠΎ вакансии ΠΈΠ»ΠΈ сразу Π½Π°ΠΏΡ€Π°Π²ΠΈΡ‚ΡŒ своС Ρ€Π΅Π·ΡŽΠΌΠ΅ ΠΌΠΎΠΆΠ½ΠΎ сюда: β€” Π’ΠΈΠΌΠ»ΠΈΠ΄ (Telegram) β€” HR (telegram, m.brigadnova@angaratech.ru)

APT
16 310
Nim-RunPE A Nim implementation of reflective PE-Loading from memory https://github.com/S3cur3Th1sSh1t/Nim-RunPE #nim #run #pe
Nim-RunPE A Nim implementation of reflective PE-Loading from memory https://github.com/S3cur3Th1sSh1t/Nim-RunPE #nim #run #pe #memory

APT
16 310
EmbedExeLnk Embedding an EXE inside a LNK with automatic execution https://www.x86matthew.com/view_post?id=embed_exe_lnk #embed #lnk #exe #cpp

APT
16 310
NTLM Relaying β€” A comprehensive guide This guide covers a range of techniques from most common to the lesser-known. https://www.trustedsec.com/blog/a-comprehensive-guide-on-relaying-anno-2022/ #ad #ntlm #relay #guide

APT
16 310
A Tip for SQL Injection WAF Bypass
A Tip for SQL Injection WAF Bypass

APT
16 310
LFIDump A simple python script to dump remote files through a local file read or local file inclusion web vulnerability. https://github.com/p0dalirius/LFIDump #lfi #dump #tools #bugbounty

APT
16 310
Understanding Process Ghosting in detail https://dosxuz.gitlab.io/post/processghosting/ #edr #evasion #process #ghosting #csh
Understanding Process Ghosting in detail https://dosxuz.gitlab.io/post/processghosting/ #edr #evasion #process #ghosting #csharp

APT
16 310
EvilSelenium This project weaponizes Selenium to attack Chrome. Dump saved credentials, cookies, take (authenticated) screens
EvilSelenium This project weaponizes Selenium to attack Chrome. Dump saved credentials, cookies, take (authenticated) screenshots, dump emails from gmail/o365 or chats from Whatsapp and exfiltrate & download files https://github.com/mrd0x/EvilSelenium #selenium #chrome #dump #password

APT
16 310
SysWhispers is dead, long live SysWhispers! In a journey around the fantastic tool SysWhispers, cover some of the strategies that can be adopted to detect it, both statically and dynamically. https://klezvirus.github.io/RedTeaming/AV_Evasion/NoSysWhisper/ #edr #evasion #syscall #redteam #blueteam

APT
16 310
Converting C# Tools to PowerShell In this post, we will be looking at how we can make our own PowerSharpPack by learning how
Converting C# Tools to PowerShell In this post, we will be looking at how we can make our own PowerSharpPack by learning how to convert ANY C# tool into a PowerShell script ourselves. This is useful in cases where we want to modify a specific tool’s default behavior, use a tool that hasn’t already been converted for us, or use a custom tool that we develop ourselves. https://icyguider.github.io/2022/01/03/Convert-CSharp-Tools-To-PowerShell.html

APT
16 310
#memes
#memes

APT
16 310
Early Bird Catches the Wormhole: Observations from the StellarParticle Campaign StellarParticle, an adversary campaign associ
Early Bird Catches the Wormhole: Observations from the StellarParticle Campaign StellarParticle, an adversary campaign associated with COZY BEAR, was active throughout 2021 leveraging novel tactics and techniques in supply chain attacks observed by CrowdStrike incident responders https://www.crowdstrike.com/blog/observations-from-the-stellarparticle-campaign/ #threatintel #dfir #blueteam #malware

APT
16 310
Windows Win32k β€” Local Privilege Escalation (CVE-2022-21882) https://github.com/KaLendsi/CVE-2022-21882 #windows #lpe #cve

APT
16 310
FunctionStomping This is a brand-new technique for shellcode injection to evade AVs and EDRs. This technique is inspired by M
FunctionStomping This is a brand-new technique for shellcode injection to evade AVs and EDRs. This technique is inspired by Module Stomping and has some similarities.The big advantage of this technique is that it isn't overwritting an entire module or PE, just one function and the target process can still use any other function from the target module. https://github.com/Idov31/FunctionStomping #edr #evasion #stomping #maldev #cpp

APT
16 310
SMBeagle This is fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be re
SMBeagle This is fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. https://github.com/punk-security/SMBeagle #ad #share #enum #tools

APT
16 310
List of Vulnerable Functions for Different Languages This list contains signatures for potentially vulnerable functions for numerous languages in a format suitable for use. https://rules.sonarsource.com/ https://github.com/wireghoul/graudit #appsec #vulnerable #function #source

APT
16 310
Cobalt Strike, a Defender’s Guide In this research, exposes adversarial Tactics, Techniques and Procedures (TTPs) as well as
Cobalt Strike, a Defender’s Guide In this research, exposes adversarial Tactics, Techniques and Procedures (TTPs) as well as the tools use to execute mission objectives. In most of cases, the threat actors utilizing Cobalt Strike. Therefore, defenders should know how to detect Cobalt Strike in various stages of its execution. The primary purpose of this articles is to expose the most common techniques from the intrusions track and provide detections. Having said that, not all of Cobalt Strike’s features will be discussed. # https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/ # https://thedfirreport.com/2022/01/24/cobalt-strike-a-defenders-guide-part-2/ #cobaltstrike #research #blueteam

APT
16 310
PwnKit: Local Privilege Escalation Vulnerability in Polkit’s Pkexec (CVE-2021-4034) The Qualys Research Team has discovered a
PwnKit: Local Privilege Escalation Vulnerability in Polkit’s Pkexec (CVE-2021-4034) The Qualys Research Team has discovered a memory corruption vulnerability in polkit’s pkexec, a SUID-root program that is installed by default on every major Linux distribution. This easily exploited vulnerability allows any unprivileged user to gain full root privileges on a vulnerable host by exploiting this vulnerability in its default configuration. Research: https://blog.qualys.com/vulnerabilities-threat-research/2022/01/25/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034 PoC: https://github.com/arthepsy/CVE-2021-4034 Exploit: https://github.com/berdav/CVE-2021-4034 #linux #lpe #polkit #cve

APT
16 310
Linux Root PrivEsc and Escaping Containers (CVE-2022-0185) Research: https://www.willsroot.io/2022/01/cve-2022-0185.html Exploit: https://github.com/Crusaders-of-Rust/CVE-2022-0185 #linux #kernel #lpe #escape #container #0day

APT
16 310
SonicWall SMA-100 Unauth RCE Bad Blood is an exploit for CVE-2021-20038, a stack-based buffer overflow in the httpd binary of SMA-100 series systems using firmware versions 10.2.1.x. The exploit, as written, will open up a telnet bind shell on port 1270. An attacker that connects to the shell will achieve execution as nobody. Research: https://attackerkb.com/topics/QyXRC1wbvC/cve-2021-20038/rapid7-analysis Exploit: https://github.com/jbaines-r7/badblood #sonicwall #exploit #rce #cve