es
Feedback
APT

APT

Ir al canal en Telegram

This channel discusses: — Offensive Security — RedTeam — Malware Research — OSINT — etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat

Mostrar más

📈 Análisis del canal de Telegram APT

El canal APT (@apt_notes) en el segmento lingüístico de Inglés es un actor destacado. Actualmente la comunidad reúne a 16 245 suscriptores, ocupando la posición 7 769 en la categoría Tecnologías y Aplicaciones y el puesto 40 381 en la región Rusia.

📊 Métricas de audiencia y dinámica

Desde su creación el невідомо, el proyecto ha mostrado un crecimiento acelerado, reuniendo a 16 245 suscriptores.

Según los últimos datos del 30 agosto, 2026, el canal mantiene una actividad estable. En los últimos 30 días la variación de miembros fue de 549, y en las últimas 24 horas de 10, conservando un alto alcance.

  • Estado de verificación: No verificado
  • Tasa de interacción (ER): El promedio de interacción de la audiencia es 39.89%. Durante las primeras 24 horas tras publicar, el contenido suele obtener 18.07% de reacciones respecto al total de suscriptores.
  • Alcance de las publicaciones: Cada publicación recibe en promedio 6 477 visualizaciones. En el primer día suele acumular 2 934 visualizaciones.
  • Reacciones e interacción: La audiencia responde de forma activa: el promedio de reacciones por publicación es 26.

📝 Descripción y política de contenido

El autor describe el recurso como un espacio para expresar opiniones subjetivas:
This channel discusses: — Offensive Security — RedTeam — Malware Research — OSINT — etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat

Gracias a la alta frecuencia de actualizaciones (últimos datos recibidos el 31 agosto, 2026), el canal mantiene la vigencia y un amplio alcance. La analítica demuestra que la audiencia interactúa activamente con el contenido, lo que lo convierte en un punto de referencia dentro de la categoría Tecnologías y Aplicaciones.

16 245
Suscriptores
+1024 horas
+957 días
+54930 días
Archivo de publicaciones
APT
16 249
😡 Brute-Ratel-C4-Community-Kit This repository contains scripts, configurations and deprecated payload loaders for Brute Ratel C4. Anything which is added in the deprecated folder will not be a part of the latest release of BRc4. https://github.com/paranoidninja/Brute-Ratel-C4-Community-Kit #c2 #bof #shellcode #injection

APT
16 249
📡 Relaying to ADFS Attacks Praetorian has developed and is releasing an open source tool ADFSRelay and NTLMParse, which can be used for performing relaying attacks targeting ADFS and analyzing NTLM messages respectively. https://www.praetorian.com/blog/relaying-to-adfs-attacks/ #ad #adfs #relay #ntlm

APT
16 249
Repost from SHADOW:Group
​​🐘 Удаленная эксплуатация переполнения кучи в веб-приложениях PHP (CVE 2022-31626) Представлен PoC для RCE уязвимости в PHP <=7.4.29, которая может быть запущена через мошеннический сервер MySQL/MariaDB. Ссылка на PoC #web #rce

APT
16 249
🦠 Mangle Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL). Mangle can remove known Indicators of Compromise (IoC) based strings and replace them with random characters, change the file by inflating the size to avoid EDRs, and can clone code-signing certs from legitimate files. In doing so, Mangle helps loaders evade on-disk and in-memory scanners. https://github.com/optiv/Mangle #av #edr #memory #evasion #redteam

APT
16 249
😈 How to Detect Linux Anti-Forensics Log Tampering When forensically examining Linux systems for malicious intrusion, respon
😈 How to Detect Linux Anti-Forensics Log Tampering When forensically examining Linux systems for malicious intrusion, responders often rely on the following three artefacts to determine logins and logouts: — /var/run/utmp – currently logged in users — /var/run/wtmp – current, past logins and system reboot — /var/log/btmp – bad login attempts Of course, these artefacts are not all you can forensically investigate for malicious access, however, these will be the focus of this anti-forensics blog post. https://www.inversecos.com/2022/06/detecting-linux-anti-forensics-log.html #linux #log #evasion #antiforensics

APT
16 249
🦠 Hiding C2 Traffic Using Tyk.io A small article on the topic of hiding your malicious C2 traffic through of the TYK cloud A
🦠 Hiding C2 Traffic Using Tyk.io A small article on the topic of hiding your malicious C2 traffic through of the TYK cloud API management service domains. Tyk API gateway will let you manage your API ingress and routing them to different endpoints, some of them could be internally but some of them could be publicly exposed, and you can add some controls for authentication purposes while calling one of your APIs. 🔗 https://shells.systems/oh-my-api-abusing-tyk-cloud-api-management-service-to-hide-your-malicious-c2-traffic/ #c2 #rederectors #trafific #redteam

APT
16 249
How it started: “I waited 2 years for this, rewrote impacket for this, asked cryptographers to remake algos in python for thi
How it started: “I waited 2 years for this, rewrote impacket for this, asked cryptographers to remake algos in python for this, spent enormous time of my life to make this happen. and it's finally here this finally works and I can't find the words to express my satisfaction.” (SkelSec)

APT
16 249
🐙🐍 OctoPwn & OctoPwnWeb Pentest framework running (almost) entirely in the browser via pyodide. OctoPwnWeb has been presented a41con. Talk: https://youtu.be/jStdrDHTmD4 Slides: https://docs.google.com/presentation/d/1XQFYr_OBI1lrpybsLrHWTWcYNZcF_zOmGDHiIBwSMng Tool: http://octopwn.porchetta.industries/ Repository: https://github.com/skelsec/octopwnweb Readme: http://octopwn.porchetta.industries/readme.html Sponsor for more features: https://porchetta.industries #pentest #framework

APT
16 249
🧲 PoC for MS-DFSNM coerce authentication using NetrDfsRemoveStdRoot method Spooler service disabled, RPC filters installed t
🧲 PoC for MS-DFSNM coerce authentication using NetrDfsRemoveStdRoot method Spooler service disabled, RPC filters installed to prevent PetitPotam and File Server VSS Agent Service not installed but you still want to relay DC authentication to ADCS? Don't worry MS-DFSNM have your back: 🔗 https://github.com/Wh04m1001/DFSCoerce Inspired by: 🔗 https://github.com/topotam/PetitPotam 🔗 https://github.com/ShutdownRepo/ShadowCoerce 🔗 https://github.com/leechristensen/SpoolSample #authentication #coercion #petitpotam #ms-dfsnm

APT
16 249
Repost from RedTeam brazzers
Меньше месяца назад вышло исследование под названием "Уязвимости и атаки на CMS Bitrix". Вдохновившись этим исследованием, мой коллега Юрий (Компания BSS-Security) докрутил один из путей до RCE. Пообшавшись с разработчиками и убедившись, что уязвимость в последней версии устранена - со спокойной душой выкладываем разбор и PoC уязвимости. Ну и как всегда рекомендация - обновляйтесь вовремя))

APT
16 249
⚔️ Remote Code Injection by Abusing CreateProcess and GetEnvironmentVariable New method of injecting code into a remote process without using WriteProcessMemory. CreateProcess: https://www.x86matthew.com/view_post?id=proc_env_injection GetEnvironmentVariable: https://x-c3ll.github.io/posts/GetEnvironmentVariable-Process-Injection/ #maldev #process #inject #pinvoke #winapi

APT
16 249
📜 Defused That SAN Flag One more post about Microsoft's recent security updates - re changes to Kerberos and the new certifi
📜 Defused That SAN Flag One more post about Microsoft's recent security updates - re changes to Kerberos and the new certificate extension containing the requester's SID. The changes 'defuse' the impact of the flag that allows adding custom subject alternative names to any certificate (including the ones that 'actually' should be auto-enrolled). https://elkement.blog/2022/06/13/defused-that-san-flag/ #ad #adcs #privesc #redteam

APT
16 249
🔍 GitHub Dorks Many people ask me how to do GitHub reconnaissance, find credentials and other information Pentest or RedTeam
+3
🔍 GitHub Dorks Many people ask me how to do GitHub reconnaissance, find credentials and other information Pentest or RedTeam might need. This post will look at some ways to search GitHub. #github #dorks #recon #osint

APT
16 249
🔑 Extracting Credentials from Chrome Memory An excellent study on how Chrome's memory works and how to extract credentials, cookies, etc. in а low privileges plain text format. https://www.cyberark.com/resources/threat-research-blog/extracting-clear-text-credentials-directly-from-chromium-s-memory #chrome #memory #dump #creds

APT
16 249
Repost from Codeby
🔥 Фильм о команде Codeby на The Standoff 2022 Друзья, уже в скором времени мы будем готовы представить вам документальный фильм об участии команды Codeby на мероприятии The Standoff 2022! Вспомним, какие эмоции испытывали все мы каждый день соревнований, а также узнаем, что происходило в эти дни от лица игроков. А пока предлагаем вам насладиться просмотром небольшого трейлера!

APT
16 249
⚙️ Active Directory Delegation Management Tool Is an Active Directory delegation management tool. It allows you to make a det
⚙️ Active Directory Delegation Management Tool Is an Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest, along with their potential issues: — Objects owned by users — Objects with ACEs for users — Non canonical ACL — Disabled ACL inheritance — Default ACL modified in schema — Deleted delegation trustees It also allows you to document your delegation model in JSON files, to obtain a more readable view: https://github.com/mtth-bfft/adeleg #ad #delegations #ace #acl #tools

APT
16 249
🕵️ OSINT Collection Collection of 4000+ OSINT resources https://metaosint.github.io/table/ #osint #recon #collection
🕵️ OSINT Collection Collection of 4000+ OSINT resources https://metaosint.github.io/table/ #osint #recon #collection

APT
16 249
📒Simulating attacks with Sysmon SysmonSimulator is an Open source Windows event simulation utility created in C language, th
📒Simulating attacks with Sysmon SysmonSimulator is an Open source Windows event simulation utility created in C language, that can be used to simulate most of the attacks using WINAPIs. This can be used by Blue teams for testing the EDR detections and correlation rules. I have created it to generate attack data for the relevant Sysmon Event IDs. Attack coverage: — Process Events — File Events — Named Pipes Events — Registry Actions — Image Loading — Network Connections — Create Remote Thread — Raw Access Read — DNS Query — WMI Events — Clipboard Capture — Process Image Tampering Research: https://rootdse.org/posts/understanding-sysmon-events/ Tool: https://github.com/ScarredMonk/SysmonSimulator #sysmon #simulator #blueteam #lab