en
Feedback
APT ANALYSIS

APT ANALYSIS

Open in Telegram

Анализ APT с фокусом на моделирование, обнаружение и управление сложными атаками. Предоставление точных данных и решений для прогнозирования угроз с реальным опытом в области безопасности.

Show more
1 685
Subscribers
No data24 hours
+27 days
+1430 days
Posts Archive
♣️Next.js, cache & chains : the stale elixir (CVE-2024-46982) 🌟Blog : https://zhero-web-sec.github.io/research-and-things/ne
♣️Next.js, cache & chains : the stale elixir (CVE-2024-46982) 🌟Blog : https://zhero-web-sec.github.io/research-and-things/nextjs-cache-and-chains-the-stale-elixir ⭐️@APTANALYSIS

♣️Under the cloak of UEFI Secure Boot: Introducing CVE-2024-7344 The story of a signed UEFI application allowing a UEFI Secur
♣️Under the cloak of UEFI Secure Boot: Introducing CVE-2024-7344
The story of a signed UEFI application allowing a UEFI Secure Boot bypass
🔥Blog : https://www.welivesecurity.com/en/eset-research/under-cloak-uefi-secure-boot-introducing-cve-2024-7344 ⭐️@APTANALYSIS

♣️Create Vulnerable Looking Endpoints to Detect and Mislead Attackers 🌟Blog : https://utkusen.substack.com/p/how-to-create-v
♣️Create Vulnerable Looking Endpoints to Detect and Mislead Attackers 🌟Blog : https://utkusen.substack.com/p/how-to-create-vulnerable-looking ♣️Microsoft Configuration Manager (ConfigMgr) 2403 Unauthenticated SQL injections (CVE-2024-43468) ⚰️Blog/PoC : https://www.synacktiv.com/advisories/microsoft-configuration-manager-configmgr-2403-unauthenticated-sql-injections ⭐️@APTANALYSIS

Repost from N/a

♣️Exploitation Walkthrough and Techniques - Ivanti Connect Secure RCE (CVE-2025-0282) 🤍Blog : https://labs.watchtowr.com/exp
♣️Exploitation Walkthrough and Techniques - Ivanti Connect Secure RCE (CVE-2025-0282) 🤍Blog : https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282 ⭐️@APTANALYSIS

♣️Rusty PE Packer 🌟Repo : https://github.com/Azr43lKn1ght/Rusty-PE-Packer ⭐️@APTANALYSIS
♣️Rusty PE Packer 🌟Repo : https://github.com/Azr43lKn1ght/Rusty-PE-Packer ⭐️@APTANALYSIS

♣️Exploiting SSTI in a Modern Spring Boot Application (3.3.4) 🚬Blog : https://modzero.com/en/blog/spring_boot_ssti ⭐️@APTANA
♣️Exploiting SSTI in a Modern Spring Boot Application (3.3.4) 🚬Blog : https://modzero.com/en/blog/spring_boot_ssti ⭐️@APTANALYSIS

♣️Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation ⚰️Blog : https://cloud.google.com/blog/topics/threat-intell
♣️Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation ⚰️Blog :  https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day ⭐️@APTANALYSIS

♣️Dumping LSASS.exe Process Memory (Windows Defender Bypass) 📹 Video : https://youtu.be/GoxR7W6vjns?si=D9b_rpN4tqRb_0rd ⭐️@A
♣️Dumping LSASS.exe Process Memory (Windows Defender Bypass) 📹 Video : https://youtu.be/GoxR7W6vjns?si=D9b_rpN4tqRb_0rd ⭐️@APTANALYSIS

♣️ksmbd vulnerability research(CVE-2024-5028x) 👁Blog : https://blog.doyensec.com/2025/01/07/ksmbd-1.html ⭐️@APTANALYSIS
♣️ksmbd vulnerability research(CVE-2024-5028x) 👁Blog : https://blog.doyensec.com/2025/01/07/ksmbd-1.html ⭐️@APTANALYSIS

♣️Building a RuntimeInstaller Payload Pipeline to Evade AV Detection 👁‍🗨Blog : https://practicalsecurityanalytics.com/build
♣️Building a RuntimeInstaller Payload Pipeline to Evade AV Detection 👁‍🗨Blog : https://practicalsecurityanalytics.com/building-a-runtimeinstaller-payload-pipeline-to-evade-av-detection ⭐️@APTANALYSIS

♣️Bypass BitLocker encryption on Windows 11 (Memory Dump) 😂Blog : https://noinitrd.github.io/Memory-Dump-UEFI ⭐️@APTANALYSIS
♣️Bypass BitLocker encryption on Windows 11 (Memory Dump) 😂Blog : https://noinitrd.github.io/Memory-Dump-UEFI ⭐️@APTANALYSIS

♣️Clematis : converting PE files (EXE/DLL) into position-independent shellcode 🌟Repo : https://github.com/CBLabresearch/clem
♣️Clematis : converting PE files (EXE/DLL) into position-independent shellcode 🌟Repo :  https://github.com/CBLabresearch/clematis ⭐️@APTANALYSIS

♣️CVE-2024-12908 : Delinea Protocol Handler - Remote Code Execution via Update Process 😈Blog : https://blog.amberwolf.com/bl
♣️CVE-2024-12908 : Delinea Protocol Handler - Remote Code Execution via Update Process 😈Blog : https://blog.amberwolf.com/blog/2024/december/cve-2024-12908-delinea-protocol-handler---remote-code-execution-via-update-process ⭐️@APTANALYSIS

♣️Fancy Bear APT28 Adversary Simulation ⛓Blog : https://medium.com/@S3N4T0R/fancy-bear-apt28-adversary-simulation-e5b019668df
♣️Fancy Bear APT28 Adversary Simulation ⛓Blog : https://medium.com/@S3N4T0R/fancy-bear-apt28-adversary-simulation-e5b019668dfa ⭐️@APTANALYSIS

♣️CVE-2024-54150 : Another JWT Algorithm Confusion 🌟Blog : https://pentesterlab.com/blog/another-jwt-algorithm-confusion-cve
♣️CVE-2024-54150 : Another JWT Algorithm Confusion 🌟Blog : https://pentesterlab.com/blog/another-jwt-algorithm-confusion-cve-2024-54150 ⭐️@APTANALYSIS