APT
This channel discusses: — Offensive Security — RedTeam — Malware Research — OSINT — etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat
Show more📈 Analytical overview of Telegram channel APT
Channel APT (@apt_notes) in the English language segment is an active participant. Currently, the community unites 16 325 subscribers, ranking 7 749 in the Technologies & Applications category and 40 394 in the Russia region.
📊 Audience metrics and dynamics
Since its creation on невідомо, the project has demonstrated rapid growth, gathering an audience of 16 325 subscribers.
According to the latest data from 03 September, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by 546 over the last 30 days and by 26 over the last 24 hours, overall reach remains high.
- Verification status: Not verified
- Engagement rate (ER): The average audience engagement rate is 54.39%. Within the first 24 hours after publication, content typically collects 13.17% reactions from the total number of subscribers.
- Post reach: On average, each post receives 8 865 views. Within the first day, a publication typically gains 2 146 views.
- Reactions and interaction: The audience actively supports content: the average number of reactions per post is 13.
📝 Description and content policy
The author describes the resource as a platform for expressing subjective opinions:
“This channel discusses:
— Offensive Security
— RedTeam
— Malware Research
— OSINT
— etc
Disclaimer:
t.me/APT_Notes/6
Chat Link:
t.me/APT_Notes_PublicChat”
Thanks to the high frequency of updates (latest data received on 04 September, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.
test\nAnd put KKK in all fields. All fields will be replaced with this payload.\n\nIt will find trivial XSS and SQLi.","datePublished":"2021-07-05T01:01:06Z","dateModified":"2021-07-05T01:01:06Z","author":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"publisher":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":92},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":1}]}},{"@type":"ListItem","position":13,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/115","url":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/115","mainEntityOfPage":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/115","headline":"2/n This is an example trick to change the false returned body to true. And this is a very common use case. T…","articleBody":"2/n\nThis is an example trick to change the false returned body to true.\nAnd this is a very common use case. \n\nThe major trick for today: Injecting payloads into forms instead of typing out the entire payload.","datePublished":"2021-07-05T01:01:06Z","dateModified":"2021-07-05T01:01:06Z","author":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"publisher":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":83}]}},{"@type":"ListItem","position":14,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/114","url":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/114","mainEntityOfPage":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/114","headline":"1/n False2True trick, when access to a resource for the user is unauthorized. By changing server response bod…","articleBody":"1/n False2True trick, when access to a resource for the user is unauthorized.\nBy changing server response body from F to T in burp response body match and replace, there are great chances it can un-hide client-side controls.\n\n1. Add Match and replace.\n2. Add shown replacement.","datePublished":"2021-07-05T01:01:06Z","dateModified":"2021-07-05T01:01:06Z","author":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"publisher":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":87}]}},{"@type":"ListItem","position":15,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/113","url":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/113","mainEntityOfPage":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/113","headline":"#BurpHacksForBounties - Day 2/30 Effective usage of Match and Replace feature of Burp Suite False2True Trick…","articleBody":"#BurpHacksForBounties - Day 2/30\n\nEffective usage of Match and Replace feature of Burp Suite \n\nFalse2True Trick & Injecting all fields with polyglot payloads 😉😉\n\nHow to thread 🧵👇\n\n#infosec #security #appsec #burp #bugbounty #bugbountytips","datePublished":"2021-07-05T01:00:08Z","dateModified":"2021-07-05T01:00:08Z","author":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"publisher":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":84}]}},{"@type":"ListItem","position":16,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/112","url":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/112","mainEntityOfPage":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/112","headline":"Snaffler Snaffler - Gets a list of Windows computers from Active Directory, then spreads out its snaffly appe…","articleBody":"Snaffler \n\nSnaffler - Gets a list of Windows computers from Active Directory, then spreads out its snaffly appendages to them all to figure out which ones have file shares, and whether you can read them\n\nhttps://github.com/SnaffCon/Snaffler\n\n\n#pentest","datePublished":"2021-07-04T16:37:27Z","dateModified":"2021-07-04T16:37:27Z","author":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"publisher":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":85}]}},{"@type":"ListItem","position":17,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/111","url":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/111","mainEntityOfPage":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/111","headline":"n/n You can do almost anything with Python inside Burp. Eg. - Handle custom login - Tailored testing - Filter…","articleBody":"n/n\nYou can do almost anything with Python inside Burp.\nEg.\n- Handle custom login\n- Tailored testing\n- Filter out requests on \"interesting\" responses\n- Scale your testing\n- Add rate limiting, pipeline, etc\n\nThis approach can overcome intruder multithreading deficiencies in CE.","datePublished":"2021-07-04T01:01:06Z","dateModified":"2021-07-04T01:01:06Z","author":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"publisher":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":93},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":1}]}},{"@type":"ListItem","position":18,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/110","url":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/110","mainEntityOfPage":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/110","headline":"3/n Details in comments. Code: https://gist.github.com/r0hi7/47e3d47efaa1ee3df63a6e936dade787 Increase concur…","articleBody":"3/n\nDetails in comments.\nCode: https://gist.github.com/r0hi7/47e3d47efaa1ee3df63a6e936dade787\n\nIncrease concurrency or can add pipeline. \nThen click attack.","datePublished":"2021-07-04T01:01:06Z","dateModified":"2021-07-04T01:01:06Z","author":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"publisher":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":96},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":1}]}},{"@type":"ListItem","position":19,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/109","url":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/109","mainEntityOfPage":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/109","headline":"2/n Once you send req to the plugin, a python editor will open. This will show a couple of existing python sc…","articleBody":"2/n\nOnce you send req to the plugin, a python editor will open. This will show a couple of existing python scripts to take reference from and to use.","datePublished":"2021-07-04T01:01:06Z","dateModified":"2021-07-04T01:01:06Z","author":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"publisher":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":95},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":1}]}},{"@type":"ListItem","position":20,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/108","url":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/108","mainEntityOfPage":"https://telemetr.io/en/channels/1390210355-apt_notes/posts/108","headline":"1/n Using: CE so that everyone can explore. Intruder in CE is limited in multithreading, Turbo-Intruder can o…","articleBody":"1/n \nUsing: CE so that everyone can explore.\nIntruder in CE is limited in multithreading, Turbo-Intruder can overcome that.\n- Install through Extender\n- Send req to the plugin.","datePublished":"2021-07-04T01:01:06Z","dateModified":"2021-07-04T01:01:06Z","author":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"publisher":{"@type":"Organization","name":"APT","url":"https://telemetr.io/en/channels/1390210355-apt_notes","image":"https://img.tlmtr.io/c/1w5bdF/5386640763535865221?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":93},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":1}]}}]}
16 326owerHub - post exploitation tool based on a web application
https://reconshell.com/powerhub-post-exploitation-tool-based-on-a-web-application/
#PowerHub #PowerSploit #PowerView #Kerberos #LPE #PowerShell
16 326charlotte – fully undetected shellcode launcher
#shellcode #msfvenom #XOR #ShellcodeLauncher #CobaltStrike #Payload
https://reconshell.com/charlotte-fully-undetected-shellcode-launcher/
16 326red shadow - Lightspin AWS Vulnerability Scanner
https://reconshell.com/red-shadow-lightspin-aws-vulnerability-scanner/
#PrivilegeEscalation #exploit #Exploitation #AWS
#Vulnerability #Scanner
16 326Link to stokfredrik blog on Burp Suite:
https://portswigger.net/blog/burp-suite-tips-from-power-user-and-hackfluencer-stok
A must-read for beginners.
16 326
🍺🤡 #BurpHacksForBounties - Day 4/30
Don't ignore junk-looking information in Burp Suite.
Keep this setting on, and play with zipped data in Burp Suite.
🤫🤫 You can change zipped data in req
Learned from @stokfredrik
#infosec #appsec #security #burp #bugbountytips #bugbountytip
16 3263/n
Can be used to discover the request sent by script from the browser and learn it to craft your valid payload request to that endpoint.
More references:
https://portswigger.net/burp/documentation/desktop/functions/search
16 326
+12/n
A new window will open up which will show the references and location of those references as well.
Location can be a repeater, scanner, etc.
The reference can be in Request, Response, Headers. Will be highlighted like the one shown in the image.
16 326
♥️ #BurpHacksForBounties - Day 3/30 ♥️
🔍🔎
Find References: The most underrated and underused feature of Burp Suite
Pro Only & Can find references for URIs across the entire Burp.
A short thread : 🧵👇
#infosec #appsec #security #burp #bugbountytip #bugbountytips
16 3263/n
The above match and replace rule will replace all KKK in the request body to SQLi and XSS polyglot.
Say I use this :
'"><script src="somesrc"></script><h1>test
And put KKK in all fields. All fields will be replaced with this payload.
It will find trivial XSS and SQLi.
16 326
2/n
This is an example trick to change the false returned body to true.
And this is a very common use case.
The major trick for today: Injecting payloads into forms instead of typing out the entire payload.
16 326
+21/n False2True trick, when access to a resource for the user is unauthorized.
By changing server response body from F to T in burp response body match and replace, there are great chances it can un-hide client-side controls.
1. Add Match and replace.
2. Add shown replacement.
16 326
#BurpHacksForBounties - Day 2/30
Effective usage of Match and Replace feature of Burp Suite
False2True Trick & Injecting all fields with polyglot payloads 😉😉
How to thread 🧵👇
#infosec #security #appsec #burp #bugbounty #bugbountytips
16 326Snaffler
Snaffler - Gets a list of Windows computers from Active Directory, then spreads out its snaffly appendages to them all to figure out which ones have file shares, and whether you can read them
https://github.com/SnaffCon/Snaffler
#pentest
16 326n/n
You can do almost anything with Python inside Burp.
Eg.
- Handle custom login
- Tailored testing
- Filter out requests on "interesting" responses
- Scale your testing
- Add rate limiting, pipeline, etc
This approach can overcome intruder multithreading deficiencies in CE.
16 326
3/n
Details in comments.
Code: https://gist.github.com/r0hi7/47e3d47efaa1ee3df63a6e936dade787
Increase concurrency or can add pipeline.
Then click attack.
16 326
2/n
Once you send req to the plugin, a python editor will open. This will show a couple of existing python scripts to take reference from and to use.
16 326
1/n
Using: CE so that everyone can explore.
Intruder in CE is limited in multithreading, Turbo-Intruder can overcome that.
- Install through Extender
- Send req to the plugin.
'"><script src="somesrc"></script><h1>test
And put KKK in all fields. All fields will be replaced with this payload.
It will find trivial XSS and SQLi.