APT ANALYSIS
1.73K subscribers
171 photos
2 videos
6 files
176 links
Анализ APT с фокусом на моделирование, обнаружение и управление сложными атаками. Предоставление точных данных и решений для прогнозирования угроз с реальным опытом в области безопасности.
Download Telegram
🛡CrystalDump
🔖Dump lsass using only NTAPI functions by hand-crafting Minidump files without MiniDumpWriteDump
💥Repo : https://github.com/ricardojoserf/NativeDump/tree/crystal-flavour
💥Blog : https://ricardojoserf.github.io/nativedump
⭐️@APTANALYSIS
♣️How an obscure PHP footgun led to RCE in Craft CMS
💥Blog : https://www.assetnote.io/resources/research/how-an-obscure-php-footgun-led-to-rce-in-craft-cms
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Active Directory (Guide)
😈Blog : https://mayfly277.github.io/categories
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️.NET tool for remotely killing EDR with WDAC
🐈‍⬛Repo : https://github.com/logangoins/Krueger
🌟Blog : https://beierle.win/2024-12-20-Weaponizing-WDAC-Killing-the-Dreams-of-EDR
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️CVE-2024-54150 : Another JWT Algorithm Confusion
🌟Blog : https://pentesterlab.com/blog/another-jwt-algorithm-confusion-cve-2024-54150
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️CVE-2024-12908 : Delinea Protocol Handler - Remote Code Execution via Update Process
😈Blog : https://blog.amberwolf.com/blog/2024/december/cve-2024-12908-delinea-protocol-handler---remote-code-execution-via-update-process
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Clematis : converting PE files (EXE/DLL) into position-independent shellcode
🌟Repo :  https://github.com/CBLabresearch/clematis
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Bypass BitLocker encryption on Windows 11 (Memory Dump)
😂Blog : https://noinitrd.github.io/Memory-Dump-UEFI
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Building a RuntimeInstaller Payload Pipeline to Evade AV Detection
👁‍🗨Blog : https://practicalsecurityanalytics.com/building-a-runtimeinstaller-payload-pipeline-to-evade-av-detection
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️ksmbd vulnerability research(CVE-2024-5028x)
👁Blog : https://blog.doyensec.com/2025/01/07/ksmbd-1.html
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Dumping LSASS.exe Process Memory (Windows Defender Bypass)
📹 Video : https://youtu.be/GoxR7W6vjns?si=D9b_rpN4tqRb_0rd
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation
⚰️Blog :  https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Exploiting SSTI in a Modern Spring Boot Application (3.3.4)
🚬Blog : https://modzero.com/en/blog/spring_boot_ssti
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Exploitation Walkthrough and Techniques - Ivanti Connect Secure RCE (CVE-2025-0282)
🤍Blog : https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from Ripp3r VIP♠️
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Create Vulnerable Looking Endpoints to Detect and Mislead Attackers
🌟Blog : https://utkusen.substack.com/p/how-to-create-vulnerable-looking
♣️Microsoft Configuration Manager (ConfigMgr) 2403 Unauthenticated SQL injections (CVE-2024-43468)
⚰️Blog/PoC : https://www.synacktiv.com/advisories/microsoft-configuration-manager-configmgr-2403-unauthenticated-sql-injections
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM