uz
Feedback
APT

APT

Kanalga Telegram’da o‘tish

This channel discusses: — Offensive Security — RedTeam — Malware Research — OSINT — etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat

Ko'proq ko'rsatish

📈 Telegram kanali APT analitikasi

APT (@apt_notes) Ingliz til segmentidagi kanali faol ishtirokchi. Hozirda hamjamiyat 16 249 obunachidan iborat bo'lib, Texnologiyalar & Aralashmalar toifasida 7 769-o'rinni va Rossiya mintaqasida 40 381-o'rinni egallagan.

📊 Auditoriya ko‘rsatkichlari va dinamika

невідомо sanasidan buyon loyiha tez o‘sib, 16 249 obunachiga ega bo‘ldi.

30 Avgust, 2026 dagi oxirgi ma’lumotlarga ko‘ra kanal barqaror faollikka ega. Oxirgi 30 kunda obunachilar soni 549 ga, so‘nggi 24 soatda esa 10 ga o‘zgardi va umumiy qamrov yuqori darajada qolmoqda.

  • Tasdiqlash holati: Tasdiqlanmagan
  • Jalb etish (ER): Auditoriya o‘rtacha 39.89% darajada jalb etiladi. Nashrdan keyingi dastlabki 24 soatda kontent odatda umumiy obunachilar sonining 18.07% ini tashkil etuvchi reaksiyalarni to‘playdi.
  • Post qamrovi: Har bir post o‘rtacha 6 477 marta ko‘riladi; birinchi sutkada odatda 2 934 ta ko‘rish yig‘iladi.
  • Reaksiyalar va o‘zaro ta’sir: Auditoriya faol: har bir postga o‘rtacha 26 ta reaksiya keladi.

📝 Tavsif va kontent siyosati

Muallif resursni shaxsiy fikrni ifoda etish maydoni sifatida ta’riflaydi:
This channel discusses: — Offensive Security — RedTeam — Malware Research — OSINT — etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat

Yuqori yangilanish chastotasi (oxirgi ma’lumot 31 Avgust, 2026 da olingan) sababli kanal doimo dolzarb va katta qamrovli bo‘lib qoladi. Analitika auditoriya kontent bilan faol hamkorlik qilishini, uni Texnologiyalar & Aralashmalar toifasidagi muhim ta’sir nuqtasiga aylantirishini ko‘rsatadi.

16 249
Obunachilar
+1024 soatlar
+957 kunlar
+54930 kunlar
Postlar arxiv
APT
16 260
DNS Abuse & Misconfiguration The History of DNS Vulnerabilities and the Cloud https://unit42.paloaltonetworks.com/dns-vulnerabilities/ Dangling Domains: Security Threats, Detection and Prevalence https://unit42.paloaltonetworks.com/dangling-domains/ Fishing the AWS IP Pool for Dangling Domains https://bishopfox.com/blog/fishing-the-aws-ip-pool-for-dangling-domains Respect My Authority – Hijacking Broken Nameservers to Compromise Your Target https://thehackerblog.com/respect-my-authority-hijacking-broken-nameservers-to-compromise-your-target/ The Orphaned Internet – Taking Over 120K Domains via a DNS Vulnerability in AWS, Google Cloud, Rackspace and Digital Ocean https://thehackerblog.com/the-orphaned-internet-taking-over-120k-domains-via-a-dns-vulnerability-in-aws-google-cloud-rackspace-and-digital-ocean/ The .io Error – Taking Control of All .io Domains With a Targeted Registration https://thehackerblog.com/the-io-error-taking-control-of-all-io-domains-with-a-targeted-registration/ The International Incident – Gaining Control of a .int Domain Name With DNS Trickery https://thehackerblog.com/the-international-incident-gaining-control-of-a-int-domain-name-with-dns-trickery/ Hostile Subdomain Takeover using Heroku/Github/Desk + more https://labs.detectify.com/2014/10/21/hostile-subdomain-takeover-using-herokugithubdesk-more/ Dangling DNS: Amazon EC2 IPs https://blog.melbadry9.xyz/dangling-dns/aws/ddns-ec2-current-state Eliminating Dangling Elastic IP Takeovers with Ghostbuster https://blog.assetnote.io/2022/02/13/dangling-eips/ Internet-Wide Analysis of Subdomain Takeovers https://redhuntlabs.com/blog/project-resonance-wave-1.html Subdomain Takeover https://0xpatrik.com/subdomain-takeover-basics/ https://0xpatrik.com/subdomain-takeover-candidates/ https://0xpatrik.com/takeover-proofs/ https://0xpatrik.com/subdomain-takeover-ns/ https://0xpatrik.com/subdomain-takeover/ #dns #abuse #aws #elastic #subdomain #takeover

APT
16 260
Certipy 2.0: BloodHound, New Escalations, Shadow Credentials, Golden Certificates, and more! Blog: https://research.ifcr.dk/certipy-2-0-bloodhound-new-escalations-shadow-credentials-golden-certificates-and-more-34d1c26f0dc6 Tool: https://github.com/ly4k/Certipy #ad #adcs #abuse #tools

APT
16 260
LOLBIN — wlrmdr Action on click: wlrmdr.exe -s 60000 -f 1 -t "Important" -m "Click this dude!" -a 10 -u cmd You can use "-a 1
+1
LOLBIN — wlrmdr Action on click: wlrmdr.exe -s 60000 -f 1 -t "Important" -m "Click this dude!" -a 10 -u cmd You can use "-a 11" to skip the click requirement and spawn your process immediately: wlrmdr -s 0 -f 0 -t 0 -m 0 -a 11 -u cmd #windows #wlrmdr #lolbin #lolbas

APT
16 260
DumpSMBShare A script to dump files and folders remotely from a Windows SMB share. https://github.com/p0dalirius/DumpSMBShare
DumpSMBShare A script to dump files and folders remotely from a Windows SMB share. https://github.com/p0dalirius/DumpSMBShare #ad #smb #share #dump

APT
16 260
Keeping Up with the NTLM Relay https://www.fortalicesolutions.com/posts/keeping-up-with-the-ntlm-relay #ad #ntlm #relay #adcs

APT
16 260
o365recon Script to retrieve information via O365 and AzureAD with a valid cred. https://github.com/nyxgeek/o365recon #azure
o365recon Script to retrieve information via O365 and AzureAD with a valid cred. https://github.com/nyxgeek/o365recon #azure #recon #tools

APT
16 260
Zabbix SAML Authentication Bypass (CVE-2022-23131) https://blog.sonarsource.com/zabbix-case-study-of-unsafe-session-storage #zabbix #research #auth #bypass #cve

APT
16 260
S3Scanner Scan for open S3 buckets and dump the contents Features: — Multi-threaded scanning — Supports tons of S3-compatible
S3Scanner Scan for open S3 buckets and dump the contents Features: — Multi-threaded scanning — Supports tons of S3-compatible APIs — Scans all bucket permissions to find misconfigurations — Dump bucket contents to a local folder — Docker support https://github.com/sa7mon/S3Scanner #aws #s3 #bucket #scanner

APT
16 260
Recon — Horizontal Enumeration https://aaryanapex.medium.com/bug-bounty-methodology-horizontal-enumeration-89f7cd172e6e #osint #recon #enumeration

APT
16 260
Useful Libraries for Malware Development https://captmeelo.com/redteam/maldev/2022/02/16/libraries-for-maldev.html #edr #evasion #lib #maldev #cpp

APT
16 260
CredMaster Launch a password spray / brute force attach via Amazon AWS passthrough proxies, shifting the requesting IP addres
CredMaster Launch a password spray / brute force attach via Amazon AWS passthrough proxies, shifting the requesting IP address for every authentication attempt. This dynamically creates FireProx APIs for more evasive password sprays. The following plugins are currently supported: — OWA — EWS — O365 — O365Enum — MSOL — Okta — FortinetVPN — HTTPBrute — ADFS — AzureSSO https://github.com/knavesec/CredMaster #owa #o365 #adfs #password #spraying

APT
16 260
Password Spraying and MFA Bypasses https://www.sprocketsecurity.com/blog/how-to-bypass-mfa-all-day #ntlm #password #spraying #o365 #exchange #mfa

APT
16 260
Windows Security Log Quick Reference Cheat Sheet #windows #security #log #blueteam
Windows Security Log Quick Reference Cheat Sheet #windows #security #log #blueteam

APT
16 260
New article by our researchers Mikhail Klyuchnikov and Egor Dimitrenko about unauth RCEs in VMware products: "Hunting for bug
New article by our researchers Mikhail Klyuchnikov and Egor Dimitrenko about unauth RCEs in VMware products: "Hunting for bugs in VMware: View Planner and vRealize Business for Cloud". Read the article: https://swarm.ptsecurity.com/hunting-for-bugs-in-vmware-view-planner-and-vrealize-business-for-cloud/ This is the first article about our VMware research. More to come!

APT
16 260
KrbRelay The only public tool for relaying Kerberos tickets and the only relaying framework written in C#. https://github.com
KrbRelay The only public tool for relaying Kerberos tickets and the only relaying framework written in C#. https://github.com/cube0x0/KrbRelay #ad #kerberos #relay

APT
16 260
SpoolFool: Windows Print Spooler Privilege Escalation (CVE-2022–22718) Research: https://research.ifcr.dk/spoolfool-windows-p
SpoolFool: Windows Print Spooler Privilege Escalation (CVE-2022–22718) Research: https://research.ifcr.dk/spoolfool-windows-print-spooler-privilege-escalation-cve-2022-22718-bf7752b68d81 Exploit: https://github.com/ly4k/SpoolFool #windows #print #spooler #lpe #exploit

APT
16 260
EDRChecker Checks running processes, process metadata, Dlls loaded into your current process and the each DLLs metadata, comm
EDRChecker Checks running processes, process metadata, Dlls loaded into your current process and the each DLLs metadata, common install directories, installed services and each service binaries metadata, installed drivers and each drivers metadata, all for the presence of known defensive products such as AV's, EDR's and logging tools. C# https://github.com/PwnDexter/SharpEDRChecker PowerShell https://github.com/PwnDexter/Invoke-EDRChecker #edr #checker #csharp #powershell #tools

APT
16 260
Authentication and Authorization Testing Mindmap https://drive.google.com/file/d/1Jt1wzmgG3vDhU-vppms_KhP2ffvcMlD_/view #apps
Authentication and Authorization Testing Mindmap https://drive.google.com/file/d/1Jt1wzmgG3vDhU-vppms_KhP2ffvcMlD_/view #appsec #mindmap #auth #testing

APT
16 260
Вакансия Компания Angara Security (https://www.angarasecurity.ru/) (ГК Ангара) в отдел анализа защищенности ищет эксперта по анализу защищенности приложений. Чем предстоит заниматься: Основное: — проведение анализа защищенности и тестирования на проникновение веб и/или мобильных приложений (где скилла и задора больше хватит) — поддержание в актуальном состоянии существующей базы знаний по направлению анализа защищенности приложений — улучшение качества выполнения вышеуказаных работ — участие в Red Team проектах Помимо (если будет желание и возможность): — проведение инфраструктурных тестирований на проникновение (внешка/внутряк) — тестирование с применением методов социальной инженерии — иные активности, связанные с пентестом и анализом защищенности Чего ожидаем от кандидата: — наличие общей ИБ-шной базы по операционным системам, компьютерным сетям, веб-технологиям, программированию, криптографии — адекватное понимание типовых уязвимостей и атак на приложения (хотя бы из списка OWASP на уровне "могу объяснить как работает под капотом и показать пример эксплуатации на практике") — хорошее понимание общей методологии тестирования на проникновение (какой этап за каким идет, какие действия на каждом этапе нужно выполнять, какими инструментами) — уверенное владение типовым инструментарием пентестера Что мы готовы предложить: — конкурентоспособную ЗП с годовыми премиями — разнообразие проектов и клиентов (от разовых тестирований до годовых проектов с большим интересным скоупом) — гибридный формат работы удаленка/офис (полной удаленки нет) — ДМС со стоматологией — профильные сертификации и конференции за счет работодателя — внутренние релакс-мероприятия в рамках офиса Узнать подробности о вакансии или сразу направить свое резюме можно сюда: — Тимлид (Telegram) — HR (telegram, m.brigadnova@angaratech.ru)