fa
Feedback
APT

APT

رفتن به کانال در Telegram

This channel discusses: — Offensive Security — RedTeam — Malware Research — OSINT — etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat

نمایش بیشتر

📈 تحلیل کانال تلگرام APT

کانال APT (@apt_notes) در بخش زبانی انگلیسی بازیگری فعال است. در حال حاضر جامعه شامل 16 259 مشترک است و جایگاه 7 759 را در دسته فناوری و برنامه‌ها و رتبه 40 343 را در منطقه روسيا دارد.

📊 شاخص‌های مخاطب و پویایی

از زمان ایجاد در невідомо، پروژه رشد سریعی داشته و 16 259 مشترک جذب کرده است.

بر اساس آخرین داده‌ها در تاریخ 31 اوت, 2026، کانال فعالیت پایداری دارد. در ۳۰ روز گذشته تغییر اعضا برابر 546 و در ۲۴ ساعت گذشته برابر 11 بوده و همچنان دسترسی گسترده‌ای حفظ شده است.

  • وضعیت تأیید: تأیید نشده
  • نرخ تعامل (ER): میانگین تعامل مخاطب 40.49% است و در ۲۴ ساعت نخست پس از انتشار، محتوا معمولاً 18.06% واکنش نسبت به کل مشترکان کسب می‌کند.
  • دسترسی پست‌ها: هر پست به طور میانگین 6 579 بازدید دریافت می‌کند. در اولین روز معمولاً 2 934 بازدید جمع‌آوری می‌شود.
  • واکنش‌ها و تعامل: مخاطبان به‌طور فعال حمایت می‌کنند؛ میانگین واکنش به هر پست 26 است.

📝 توضیح و سیاست محتوایی

نویسنده این فضا را محل بیان دیدگاه‌های شخصی توصیف می‌کند:
This channel discusses: — Offensive Security — RedTeam — Malware Research — OSINT — etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat

به لطف به‌روزرسانی‌های پرتکرار (آخرین داده در تاریخ 01 سپتامبر, 2026)، کانال همواره به‌روز و دارای دسترسی بالاست. تحلیل‌ها نشان می‌دهد مخاطبان به‌طور فعال با محتوا تعامل دارند و آن را به نقطه اثرگذاری مهم در دسته فناوری و برنامه‌ها تبدیل کرده‌اند.

16 259
مشترکین
+1124 ساعت
+927 روز
+54630 روز
آرشیو پست ها
APT
16 267
Suspicious Named Pipe Events https://medium.com/falconforce/falconfriday-suspicious-named-pipe-events-0xff1b-fe475d7ebd8 #windows #pipe #events #blueteam #redteam

APT
16 267
AWS IAM explained for RedTeam & BlueTeam https://infosecwriteups.com/aws-iam-explained-for-red-and-blue-teams-2dda8b20fbf7 #aws #iam #redteam #blueteam

APT
16 267
Password Hash Cracking in AWS https://www.sans.org/blog/password-hash-cracking-amazon-web-services/ #aws #cuda #hashcat

APT
16 267
Bypass EDR with Microsoft Teams Copy payload into: %userprofile%\AppData\Local\Microsoft\Teams\current\ Then: %userprofile%\A
Bypass EDR with Microsoft Teams Copy payload into: %userprofile%\AppData\Local\Microsoft\Teams\current\ Then: %userprofile%\AppData\Local\Microsoft\Teams\Update.exe --processStart payload.exe --process-start-args "args" #edr #evasion #teams

APT
16 267
Domain Escalation — ShadowCoerce (MS-FSRVP) Coercing the domain controller machine account to authenticate to a host which is
Domain Escalation — ShadowCoerce (MS-FSRVP) Coercing the domain controller machine account to authenticate to a host which is under the control of a threat actor could lead to domain compromise. The most notable technique which involves coerced authentication is the PetitPotam attack which uses the Encrypting File System Remote Protocol (MS-EFSR). However, this is not the only protocol which could be utilized for domain escalation. Research: https://pentestlaboratories.com/2022/01/11/shadowcoerce/ PoC: https://github.com/ShutdownRepo/ShadowCoerce #ad #escalation #relay #redteam

APT
16 267
Log4jHorizon A proof of concept for VMWare Horizon instances and allows attackers to execute code as an unauthenticated user
Log4jHorizon A proof of concept for VMWare Horizon instances and allows attackers to execute code as an unauthenticated user using a single HTTP request. Research: https://www.sprocketsecurity.com/blog/crossing-the-log4j-horizon-a-vulnerability-with-no-return Exploit: https://github.com/puzzlepeaches/Log4jHorizon #log4j #vmware #horizon #rce

APT
16 267
Important Windows processes for Threat Hunting https://www.socinvestigation.com/important-windows-processes-for-threat-hunting/ #edr #detection #forensic #process

APT
16 267
Malicious PDF Generator Generate ten different malicious pdf files with phone-home functionality. Can be used with Burp Collaborator. https://github.com/pussycat0x/malicious-pdf #pdf #payload #burp #collaborator

APT
16 267
Deep Technical Analysis of an Office RCE Exploit https://billdemirkapi.me/unpacking-cve-2021-40444-microsoft-office-rce/ #off
Deep Technical Analysis of an Office RCE Exploit https://billdemirkapi.me/unpacking-cve-2021-40444-microsoft-office-rce/ #office #rce #cve_2021_40444

APT
16 267
Domain Domination With Windows Shortcuts This article on malicious shortcut files and how they can be leveraged to capture NTLM hashes quietly and dominate a network or domain. https://medium.com/cybersecpadawan/domain-domination-with-windows-shortcuts-6aab1d72b793 #shortcuts #lnk #abuse #windows

APT
16 267
EDR Parallel-asis through Analysis New method for enumerating Syscalls numbers using the Parallel loader Research: https://ww
EDR Parallel-asis through Analysis New method for enumerating Syscalls numbers using the Parallel loader Research: https://www.mdsec.co.uk/2022/01/edr-parallel-asis-through-analysis/ C++ Code Snipped: https://github.com/mdsecactivebreach/ParallelSyscalls C# Code Snipped: https://github.com/cube0x0/ParallelSyscalls #edr #evasion #parallel #csharp

APT
16 267
Optimizing Windows Function Resolving: A Case Study Into GetProcAddress https://phasetw0.com/windows-internals/optimizing_function_resolving/ #edr #evasion #winapi #getprocaddress

APT
16 267
RemoteNET This library lets you examine, create and interact with remote objects in other .NET processes. It's like System.Runtime.Remoting except the other app doesn't need to be compiled (or consent) to support it. Basically this library lets you mess with objects of any other .NET app without asking for permissions https://github.com/theXappy/RemoteNET #csharp #injection #pentest

APT
16 267
Process Injection via KernelCallBackTable Process injection via the KernelCallBackTable involves replacing original callback
Process Injection via KernelCallBackTable Process injection via the KernelCallBackTable involves replacing original callback function by custom payload so that whenever the function is invoked, payload will be triggered. In this case the fnCOPYDATA callback function has been used. C# Code Snippet: https://gist.github.com/sbasu7241/5dd8c278762c6305b4b2009d44d60c13 #edr #evasion #dll #injection #kernelcallbacktable

APT
16 267
Domain Persistence – AdminSDHolder https://pentestlab.blog/2022/01/04/domain-persistence-adminsdholder/ #ad #adminsdholder #redteam

APT
16 267
An ‘Attack Path’ Mapping Approach to CVEs 2021-42287 and 2021-42278 This post provides Splunk SPL queries for detecting the attacks described in Charlie’s blog, using only Windows Security Log events from a domain controller. Furthermore, this post only examines a subset of the Windows Event logging data source https://www.trustedsec.com/blog/an-attack-path-mapping-approach-to-cves-2021-42287-and-2021-42278 #ad #pac #s4u2self #research #escalation

APT
16 267
Bypass Defender AV static detection: If you name a malicious file *.log Defender doesn't scan it. UPD: DumpStack (by any file
Bypass Defender AV static detection: If you name a malicious file *.log Defender doesn't scan it. UPD: DumpStack (by any file number) can bypass MDE easily with no detection as mimikatz or eicar mode. The malicious file can be shown in the console but not identified as malicious. #defender #evasion #tricks

APT
16 267
Phishing With Spoofed Cloud Attachments This article looks at how you can abuse the cloud attachment feature on O365 to make
Phishing With Spoofed Cloud Attachments This article looks at how you can abuse the cloud attachment feature on O365 to make executables (or any other file types) appear as harmless attachments. https://mrd0x.com/phishing-o365-spoofed-cloud-attachments/ #phishing #O365 #abuse

APT
16 267
Undetected Azure AD Bruteforce Attack In late June 2021, Secureworks Counter Threat Unit researchers discovered a flaw in the
Undetected Azure AD Bruteforce Attack In late June 2021, Secureworks Counter Threat Unit researchers discovered a flaw in the protocol used by the Azure Active Directory Seamless Single Sign-On feature. This flaw allows threat actors to perform single-factor brute-force attacks against Azure Active Directory (Azure AD) without generating sign-in events in the targeted organization’s tenant. PoC: https://github.com/treebuilder/aad-sso-enum-brute-spray Research: https://www.secureworks.com/research/undetected-azure-active-directory-brute-force-attacks #sso #azure #ad #bruteforce #research