
Seatbelt هو مشروع بلغة C# يقوم بعدد من "فحوصات السلامة" الاستقصائية للمضيف والموجهة أمنيًا، ذات الصلة بمنظوري الأمن الهجومي والدفاعي.
سيت بيلت هو مشروع بلغة C# يقوم بعدد من "فحوصات الأمان" الموجهة لمسح المضيف والتي تعتبر ذات صلة من منظور أمني هجومي ودفاعي على حد سواء.
نص برمجي HostEnum.ps1 لأندرو تشايلز ونص Get-HostProfile.ps1 لتيفكين ألهموا العديد من القطع الأثرية التي تم جمعها.
@harmj0y و @tifkin_ هما المؤلفان الأساسيان لهذا التنفيذ.
سيت بيلت مرخص بموجب رخصة BSD 3-Clause.
%&&@@@&&
&&&&&&&%%%, #&&@@@@@@%%%%%%###############%
&%& %&%% &////(((&%%%%%#%################//((((###%%%%%%%%%%%%%%%
%%%%%%%%%%%######%%%#%%####% &%%**# @////(((&%%%%%%######################(((((((((((((((((((
#%#%%%%%%%#######%#%%####### %&%,,,,,,,,,,,,,,,, @////(((&%%%%%#%#####################(((((((((((((((((((
#%#%%%%%%#####%%#%#%%####### %%%,,,,,, ,,. ,, @////(((&%%%%%%%######################(#(((#(#((((((((((
#####%%%#################### &%%...... ... .. @////(((&%%%%%%%###############%######((#(#(####((((((((
#######%##########%######### %%%...... ... .. @////(((&%%%%%#########################(#(#######((#####
###%##%%#################### &%%............... @////(((&%%%%%%%%##############%#######(#########((#####
#####%###################### %%%.. @////(((&%%%%%%%################
&%& %%%%% Seatbelt %////(((&%%%%%%%%#############*
&%%&&&%%%%% v1.2.1 ,(((&%%%%%%%%%%%%%%%%%,
#%%%%##,
Available commands (+ means remote usage is supported):
+ AMSIProviders - Providers registered for AMSI
+ AntiVirus - Registered antivirus (via WMI)
+ AppLocker - AppLocker settings, if installed
ARPTable - Lists the current ARP table and adapter information (equivalent to arp -a)
AuditPolicies - Enumerates classic and advanced audit policy settings
+ AuditPolicyRegistry - Audit settings via the registry
+ AutoRuns - Auto run executables/scripts/programs
azuread - Return AzureAD info
Certificates - Finds user and machine personal certificate files
CertificateThumbprints - Finds thumbprints for all certificate store certs on the system
+ ChromiumBookmarks - Parses any found Chrome/Edge/Brave/Opera bookmark files
+ ChromiumHistory - Parses any found Chrome/Edge/Brave/Opera history files
+ ChromiumPresence - Checks if interesting Chrome/Edge/Brave/Opera files exist
+ CloudCredentials - AWS/Google/Azure/Bluemix cloud credential files
+ CloudSyncProviders - All configured Office 365 endpoints (tenants and teamsites) which are synchronised by OneDrive.
CredEnum - Enumerates the current user's saved credentials using CredEnumerate()
+ CredGuard - CredentialGuard configuration
dir - Lists files/folders. By default, lists users' downloads, documents, and desktop folders (arguments == [directory] [maxDepth] [regex] [boolIgnoreErrors]
+ DNSCache - DNS cache entries (via WMI)
+ DotNet - DotNet versions
+ DpapiMasterKeys - List DPAPI master keys
EnvironmentPath - Current environment %PATH$ folders and SDDL information
+ EnvironmentVariables - Current environment variables
+ ExplicitLogonEvents - Explicit Logon events (Event ID 4648) from the security event log. Default of 7 days, argument == last X days.
ExplorerMRUs - Explorer most recently used files (last 7 days, argument == last X days)
+ ExplorerRunCommands - Recent Explorer "run" commands
FileInfo - Information about a file (version information, timestamps, basic PE info, etc. argument(s) == file path(s)
+ FileZilla - FileZilla configuration files
+ FirefoxHistory - Parses any found FireFox history files
+ FirefoxPresence - Checks if interesting Firefox files exist
+ Hotfixes - Installed hotfixes (via WMI)
IdleTime - Returns the number of seconds since the current user's last input.
+ IEFavorites - Internet Explorer favorites
IETabs - Open Internet Explorer tabs
+ IEUrls - Internet Explorer typed URLs (last 7 days, argument == last X days)
+ InstalledProducts - Installed products via the registry
InterestingFiles - "Interesting" files matching various patterns in the user's folder. Note: takes non-trivial time.
+ InterestingProcesses - "Interesting" processes - defensive products and admin tools
InternetSettings - Internet settings including proxy configs and zones configuration
+ KeePass - Finds KeePass configuration files
+ LAPS - LAPS settings, if installed
+ LastShutdown - Returns the DateTime of the last system shutdown (via the registry).
LocalGPOs - Local Group Policy settings applied to the machine/local users
+ LocalGroups - Non-empty local groups, "-full" displays all groups (argument == computername to enumerate)
+ LocalUsers - Local users, whether they're active/disabled, and pwd last set (argument == computername to enumerate)
+ LogonEvents - Logon events (Event ID 4624) from the security event log. Default of 10 days, argument == last X days.
+ LogonSessions - Windows logon sessions
LOLBAS - Locates Living Off The Land Binaries and Scripts (LOLBAS) on the system. Note: takes non-trivial time.
+ LSASettings - LSA settings (including auth packages)
+ MappedDrives - Users' mapped drives (via WMI)
McAfeeConfigs - Finds McAfee configuration files
McAfeeSiteList - Decrypt any found McAfee SiteList.xml configuration files.
MicrosoftUpdates - All Microsoft updates (via COM)
MTPuTTY - MTPuTTY configuration files
NamedPipes - Named pipe names, any readable ACL information and associated process information.
+ NetworkProfiles - Windows network profiles
+ NetworkShares - Network shares exposed by the machine (via WMI)
+ NTLMSettings - NTLM authentication settings
OfficeMRUs - Office most recently used file list (last 7 days)
OneNote - List OneNote backup files
+ OptionalFeatures - List Optional Features/Roles (via WMI)
OracleSQLDeveloper - Finds Oracle SQLDeveloper connections.xml files
+ OSInfo - Basic OS info (i.e. architecture, OS version, etc.)
+ OutlookDownloads - List files downloaded by Outlook
+ PoweredOnEvents - Reboot and sleep schedule based on the System event log EIDs 1, 12, 13, 42, and 6008. Default of 7 days, argument == last X days.
+ PowerShell - PowerShell versions and security settings
+ PowerShellEvents - PowerShell script block logs (4104) with sensitive data.
+ PowerShellHistory - Searches PowerShell console history files for sensitive regex matches.
Printers - Installed Printers (via WMI)
+ ProcessCreationEvents - Process creation logs (4688) with sensitive data.
Processes - Running processes with file info company names that don't contain 'Microsoft', "-full" enumerates all processes
+ ProcessOwners - Running non-session 0 process list with owners. For remote use.
+ PSSessionSettings - Enumerates PS Session Settings from the registry
+ PuttyHostKeys - Saved Putty SSH host keys
+ PuttySessions - Saved Putty configuration (interesting fields) and SSH host keys
RDCManFiles - Windows Remote Desktop Connection Manager settings files
+ RDPSavedConnections - Saved RDP connections stored in the registry
+ RDPSessions - Current incoming RDP sessions (argument == computername to enumerate)
+ RDPsettings - Remote Desktop Server/Client Settings
RecycleBin - Items in the Recycle Bin deleted in the last 30 days - only works from a user context!
reg - Registry key values (HKLM\Software by default) argument == [Path] [intDepth] [Regex] [boolIgnoreErrors]
RPCMappedEndpoints - Current RPC endpoints mapped
+ SCCM - System Center Configuration Manager (SCCM) settings, if applicable
+ ScheduledTasks - Scheduled tasks (via WMI) that aren't authored by 'Microsoft', "-full" dumps all Scheduled tasks
SearchIndex - Query results from the Windows Search Index, default term of 'passsword'. (argument(s) == <search path> <pattern1,pattern2,...>
SecPackageCreds - Obtains credentials from security packages
+ SecureBoot - Secure Boot configuration
SecurityPackages - Enumerates the security packages currently available using EnumerateSecurityPackagesA()
Services - Services with file info company names that don't contain 'Microsoft', "-full" dumps all processes
+ SlackDownloads - Parses any found 'slack-downloads' files
+ SlackPresence - Checks if interesting Slack files exist
+ SlackWorkspaces - Parses any found 'slack-workspaces' files
+ SuperPutty - SuperPutty configuration files
+ Sysmon - Sysmon configuration from the registry
+ SysmonEvents - Sysmon process creation logs (1) with sensitive data.
TcpConnections - Current TCP connections and their associated processes and services
TokenGroups - The current token's local and domain groups
TokenPrivileges - Currently enabled token privileges (e.g. SeDebugPrivilege/etc.)
+ UAC - UAC system policies via the registry
UdpConnections - Current UDP connections and associated processes and services
UserRightAssignments - Configured User Right Assignments (e.g. SeDenyNetworkLogonRight, SeShutdownPrivilege, etc.) argument == computername to enumerate
WifiProfile - Enumerates the saved Wifi profiles and extract the ssid, authentication type, cleartext key/passphrase (when possible)
+ WindowsAutoLogon - Registry autologon information
WindowsCredentialFiles - Windows credential DPAPI blobs
+ WindowsDefender - Windows Defender settings (including exclusion locations)
+ WindowsEventForwarding - Windows Event Forwarding (WEF) settings via the registry
+ WindowsFirewall - Non-standard firewall rules, "-full" dumps all (arguments == allow/deny/tcp/udp/in/out/domain/private/public)
WindowsVault - Credentials saved in the Windows Vault (i.e. logins from Internet Explorer and Edge).
+ WMI - Runs a specified WMI query
WMIEventConsumer - Lists WMI Event Consumers
WMIEventFilter - Lists WMI Event Filters
WMIFilterBinding - Lists WMI Filter to Consumer Bindings
+ WSUS - Windows Server Update Services (WSUS) settings, if applicable
Seatbelt has the following command groups: All, User, System, Slack, Chromium, Remote, Misc
You can invoke command groups with "Seatbelt.exe <group>"
Or command groups except specific commands "Seatbelt.exe <group> -Command"
"Seatbelt.exe -group=all" runs all commands
"Seatbelt.exe -group=user" runs the following commands:
azuread, Certificates, CertificateThumbprints, ChromiumPresence, CloudCredentials,
CloudSyncProviders, CredEnum, dir, DpapiMasterKeys,
ExplorerMRUs, ExplorerRunCommands, FileZilla, FirefoxPresence,
IdleTime, IEFavorites, IETabs, IEUrls,
KeePass, MappedDrives, MTPuTTY, OfficeMRUs,
OneNote, OracleSQLDeveloper, PowerShellHistory, PuttyHostKeys,
PuttySessions, RDCManFiles, RDPSavedConnections, SecPackageCreds,
SlackDownloads, SlackPresence, SlackWorkspaces, SuperPutty,
TokenGroups, WindowsCredentialFiles, WindowsVault
"Seatbelt.exe -group=system" runs the following commands:
AMSIProviders, AntiVirus, AppLocker, ARPTable, AuditPolicies,
AuditPolicyRegistry, AutoRuns, Certificates, CertificateThumbprints,
CredGuard, DNSCache, DotNet, EnvironmentPath,
EnvironmentVariables, Hotfixes, InterestingProcesses, InternetSettings,
LAPS, LastShutdown, LocalGPOs, LocalGroups,
LocalUsers, LogonSessions, LSASettings, McAfeeConfigs,
NamedPipes, NetworkProfiles, NetworkShares, NTLMSettings,
OptionalFeatures, OSInfo, PoweredOnEvents, PowerShell,
Processes, PSSessionSettings, RDPSessions, RDPsettings,
SCCM, SecureBoot, Services, Sysmon,
TcpConnections, TokenPrivileges, UAC, UdpConnections,
UserRightAssignments, WifiProfile, WindowsAutoLogon, WindowsDefender,
WindowsEventForwarding, WindowsFirewall, WMI, WMIEventConsumer,
WMIEventFilter, WMIFilterBinding, WSUS
"Seatbelt.exe -group=slack" runs the following commands:
SlackDownloads, SlackPresence, SlackWorkspaces
"Seatbelt.exe -group=chromium" runs the following commands:
ChromiumBookmarks, ChromiumHistory, ChromiumPresence
"Seatbelt.exe -group=remote" runs the following commands:
AMSIProviders, AntiVirus, AuditPolicyRegistry, ChromiumPresence, CloudCredentials,
DNSCache, DotNet, DpapiMasterKeys, EnvironmentVariables,
ExplicitLogonEvents, ExplorerRunCommands, FileZilla, Hotfixes,
InterestingProcesses, KeePass, LastShutdown, LocalGroups,
LocalUsers, LogonEvents, LogonSessions, LSASettings,
MappedDrives, NetworkProfiles, NetworkShares, NTLMSettings,
OptionalFeatures, OSInfo, PoweredOnEvents, PowerShell,
ProcessOwners, PSSessionSettings, PuttyHostKeys, PuttySessions,
RDPSavedConnections, RDPSessions, RDPsettings, SecureBoot,
Sysmon, WindowsDefender, WindowsEventForwarding, WindowsFirewall
"Seatbelt.exe -group=misc" runs the following commands:
ChromiumBookmarks, ChromiumHistory, ExplicitLogonEvents, FileInfo, FirefoxHistory,
InstalledProducts, InterestingFiles, LogonEvents, LOLBAS,
McAfeeSiteList, MicrosoftUpdates, OutlookDownloads, PowerShellEvents,
Printers, ProcessCreationEvents, ProcessOwners, RecycleBin,
reg, RPCMappedEndpoints, ScheduledTasks, SearchIndex,
SecurityPackages, SysmonEvents
Examples: 'Seatbelt.exe [Command2] ...' will run one or more specified checks only 'Seatbelt.exe -full' will return complete results for a command without any filtering. 'Seatbelt.exe " [argument]"' will pass an argument to a command that supports it (note the quotes). 'Seatbelt.exe -group=all' will run ALL enumeration checks, can be combined with "-full". 'Seatbelt.exe -group=all -AuditPolicies' will run all enumeration checks EXCEPT AuditPolicies, can be combined with "-full". 'Seatbelt.exe -computername=COMPUTER.DOMAIN.COM [-username=DOMAIN\USER -password=PASSWORD]' will run an applicable check remotely 'Seatbelt.exe -group=remote -computername=COMPUTER.DOMAIN.COM [-username=DOMAIN\USER -password=PASSWORD]' will run remote specific checks 'Seatbelt.exe -group=system -outputfile="C:\Temp\out.txt"' will run system checks and output to a .txt file. 'Seatbelt.exe -group=user -q -outputfile="C:\Temp\out.json"' will run in quiet mode with user checks and output to a .json file.
**ملاحظة:** سيتم تشغيل عمليات البحث التي تستهدف المستخدمين للمستخدم الحالي إذا لم يكن مرتفعًا، ولجميع المستخدمين إذا كان مرتفعًا.
## مجموعات الأوامر
**ملاحظة:** تقوم العديد من الأوامر ببعض أنواع التصفية افتراضيًا. يؤدي توفير الوسيطة `-full` إلى منع تصفية المخرجات. أيضًا، مجموعة الأوامر `all` ستقوم بتشغيل جميع الفحوصات الحالية.
على سبيل المثال، الأمر التالي سيقوم بتشغيل جميع الفحوصات وإرجاع جميع المخرجات:
`Seatbelt.exe -group=all -full`
### system
يقوم بتشغيل الفحوصات التي تستخرج بيانات مثيرة للاهتمام حول النظام.
يتم تنفيذه باستخدام: `Seatbelt.exe -group=system`
| الأمر | الوصف |
| ----------- | ----------- |
| AMSIProviders | المزوّدون المسجلون لـ AMSI |
| AntiVirus | برامج مكافحة الفيروسات المسجلة (عبر WMI) |
| AppLocker | إعدادات AppLocker، إذا كان مثبتًا |
| ARPTable | يعرض جدول ARP الحالي ومعلومات المحول (مكافئ لـ arp -a) |
| AuditPolicies | تعداد إعدادات سياسة التدقيق الكلاسيكية والمتقدمة |
| AuditPolicyRegistry | إعدادات التدقيق عبر السجل |
| AutoRuns | البرامج/النصوص/البرامج التي تعمل تلقائيًا |
| Certificates | ملفات الشهادات الشخصية للمستخدم والجهاز |
| CertificateThumbprints | بصمات الإبهام لجميع شهادات مخزن الشهادات على النظام |
| CredGuard | تكوين CredentialGuard |
| DNSCache | إدخالات ذاكرة التخزين المؤقت لـ DNS (عبر WMI) |
| DotNet | إصدارات .NET |
| EnvironmentPath | مجلدات `%PATH%` الحالية للبيئة ومعلومات SDDL |
| EnvironmentVariables | متغيرات بيئة المستخدم الحالي |
| Hotfixes | التحديثات السريعة المثبتة (عبر WMI) |
| InterestingProcesses | العمليات "المثيرة للاهتمام" - منتجات الحماية وأدوات الإدارة |
| InternetSettings | إعدادات الإنترنت بما في ذلك تكوينات الوكيل |
| LAPS | إعدادات LAPS، إذا كان مثبتًا |
| LastShutdown | يعرض تاريخ ووقت آخر إيقاف تشغيل للنظام (عبر السجل) |
| LocalGPOs | إعدادات نهج المجموعة المحلية المطبقة على الجهاز/المستخدمين المحليين |
| LocalGroups | المجموعات المحلية غير الفارغة، "full" يعرض جميع المجموعات (الوسيطة == اسم الحاسوب للتعداد) |
| LocalUsers | المستخدمون المحليون، سواء كانوا نشطين/معطلين، وآخر تعيين لكلمة المرور (الوسيطة == اسم الحاسوب للتعداد) |
| LogonSessions | أحداث تسجيل الدخول (معرف الحدث 4624) من سجل الأحداث الأمني. افتراضي 10 أيام، الوسيطة == آخر X أيام. |
| LSASettings | إعدادات LSA (بما في ذلك حزم المصادقة) |
| McAfeeConfigs | البحث عن ملفات تكوين McAfee |
| NamedPipes | أسماء الأنابيب المسماة ومعلومات ACL القابلة للقراءة |
| NetworkProfiles | ملفات تعريف شبكة Windows |
| NetworkShares | المشاركات الشبكية التي يعرضها الجهاز (عبر WMI) |
| NTLMSettings | إعدادات مصادقة NTLM |
| OptionalFeatures | TODO |
| OSInfo | معلومات نظام التشغيل الأساسية (مثل الهندسة، إصدار النظام، إلخ.) |
| PoweredOnEvents | جدول إعادة التشغيل والإسبات استنادًا إلى معرفات الأحداث 1 و12 و13 و42 و6008 من سجل أحداث النظام. افتراضي 7 أيام، الوسيطة == آخر X أيام. |
| PowerShell | إصدارات PowerShell وإعدادات الأمان |
| Processes | العمليات قيد التشغيل مع أسماء شركات معلومات الملف التي لا تحتوي على 'Microsoft'، "full" يعرض جميع العمليات |
| PSSessionSettings | تعداد إعدادات جلسة PS من السجل |
| RDPSessions | جلسات RDP الواردة الحالية (الوسيطة == اسم الحاسوب للتعداد) |
| RDPsettings | إعدادات خادم/عميل سطح المكتب البعيد |
| SCCM | إعدادات System Center Configuration Manager (SCCM)، إذا كانت قابلة للتطبيق |
| Services | الخدمات مع أسماء شركات معلومات الملف التي لا تحتوي على 'Microsoft'، "full" يعرض جميع الخدمات |
| Sysmon | تكوين Sysmon من السجل |
| TcpConnections | اتصالات TCP الحالية وعملياتها وخدماتها المرتبطة |
| TokenPrivileges | امتيازات الرمز الممكّنة حاليًا (مثل SeDebugPrivilege/إلخ.) |
| UAC | سياسات نظام UAC عبر السجل |
| UdpConnections | اتصالات UDP الحالية وعملياتها وخدماتها المرتبطة |
| UserRightAssignments | تعيينات حقوق المستخدم المهيأة (مثل SeDenyNetworkLogonRight، SeShutdownPrivilege، إلخ.) الوسيطة == اسم الحاسوب للتعداد |
| WifiProfile | TODO |
| WindowsAutoLogon | معلومات تسجيل الدخول التلقائي من السجل |
| WindowsDefender | إعدادات Windows Defender (بما في ذلك مواقع الاستبعاد) |
| WindowsEventForwarding | إعدادات إعادة توجيه الأحداث في Windows (WEF) عبر السجل |
| WindowsFirewall | قواعد جدار الحماية غير القياسية، "full" يعرض الكل (الوسائط == allow/deny/tcp/udp/in/out/domain/private/public) |
| WMIEventConsumer | يسرد مستهلكي أحداث WMI |
| WMIEventFilter | يسرد مرشحات أحداث WMI |
| WMIFilterBinding | يسرد روابط المرشح بالمستهلك في WMI |
| WSUS | إعدادات Windows Server Update Services (WSUS)، إذا كانت قابلة للتطبيق |
### user
يقوم بتشغيل الفحوصات التي تستخرج بيانات مثيرة للاهتمام حول المستخدم المسجل حاليًا (إذا لم يكن مرتفعًا) أو جميع المستخدمين (إذا كان مرتفعًا).
يتم تنفيذه باستخدام: `Seatbelt.exe -group=user`
| الأمر | الوصف |
| ----------- | ----------- |
| Certificates | ملفات الشهادات الشخصية للمستخدم والجهاز |
| CertificateThumbprints | بصمات الإبهام لجميع شهادات مخزن الشهادات على النظام |
| ChromiumPresence | التحقق من وجود ملفات Chrome/Edge/Brave/Opera المثيرة للاهتمام |
| CloudCredentials | ملفات بيانات اعتماد السحابة AWS/Google/Azure |
| CloudSyncProviders | TODO |
| CredEnum | تعداد بيانات الاعتماد المحفوظة للمستخدم الحالي باستخدام CredEnumerate() |
| dir | يسرد الملفات/المجلدات. افتراضيًا، يسرد مجلدات التنزيلات والمستندات وسطح المكتب للمستخدمين (الوسائط == \<directory\> \<depth\> \<regex\>) |
| DpapiMasterKeys | يسرد مفاتيح DPAPI الرئيسية |
| Dsregcmd | TODO |
| ExplorerMRUs | أحدث الملفات المستخدمة في Explorer (آخر 7 أيام، الوسيطة == آخر X أيام) |
| ExplorerRunCommands | أوامر "تشغيل" الأخيرة في Explorer |
| FileZilla | ملفات تكوين FileZilla |
| FirefoxPresence | التحقق من وجود ملفات Firefox المثيرة للاهتمام |
| IdleTime | يعرض عدد الثواني منذ آخر إدخال للمستخدم الحالي. |
| IEFavorites | المفضلة في Internet Explorer |
| IETabs | علامات تبويب Internet Explorer المفتوحة |
| IEUrls | عناوين URL المكتوبة في Internet Explorer (آخر 7 أيام، الوسيطة == آخر X أيام) |
| KeePass | TODO |
| MappedDrives | محركات الأقراص المعينة للمستخدمين (عبر WMI) |
| OfficeMRUs | قائمة أحدث الملفات المستخدمة في Office (آخر 7 أيام) |
| OneNote | TODO |
| OracleSQLDeveloper | TODO |
| PowerShellHistory | يتكرر عبر كل مستخدم محاولاً قراءة تاريخ وحدة تحكم PowerShell الخاص بهم، إذا نجح سيقوم بطباعته |
| PuttyHostKeys | مفاتيح مضيف SSH المحفوظة في Putty |
| PuttySessions | تكوين Putty المحفوظ (الحقول المثيرة للاهتمام) ومفاتيح مضيف SSH |
| RDCManFiles | ملفات إعدادات مدير اتصال سطح المكتب البعيد في Windows |
| RDPSavedConnections | اتصالات RDP المحفوظة المخزنة في السجل |
| SecPackageCreds | الحصول على بيانات الاعتماد من حزم الأمان |
| SlackDownloads | يحلل أي ملفات 'slack-downloads' موجودة |
| SlackPresence | التحقق من وجود ملفات Slack المثيرة للاهتمام |
| SlackWorkspaces | يحلل أي ملفات 'slack-workspaces' موجودة |
| SuperPutty | ملفات تكوين SuperPutty |
| TokenGroups | المجموعات المحلية والمجالات للرمز الحالي |
| WindowsCredentialFiles | بيانات اعتماد Windows بصيغة DPAPI blobs |
| WindowsVault | بيانات الاعتماد المحفوظة في Windows Vault (مثل عمليات تسجيل الدخول من Internet Explorer وEdge). |
### misc
يقوم بتشغيل جميع الفحوصات المتنوعة.
يتم تنفيذه باستخدام: `Seatbelt.exe -group=misc`
| الأمر | الوصف |
| ----------- | ----------- |
| ChromiumBookmarks | يحلل أي ملفات إشارات مرجعية موجودة لـ Chrome/Edge/Brave/Opera |
| ChromiumHistory | يحلل أي ملفات تاريخ موجودة لـ Chrome/Edge/Brave/Opera |
| ExplicitLogonEvents | أحداث تسجيل الدخول الصريح (معرف الحدث 4648) من سجل الأحداث الأمني. افتراضي 7 أيام، الوسيطة == آخر X أيام. |
| FileInfo | معلومات حول ملف (معلومات الإصدار، الطوابع الزمنية، معلومات PE الأساسية، إلخ. الوسيطة(الوسائط) == مسار(ات) الملف) |
| FirefoxHistory | يحلل أي ملفات تاريخ Firefox موجودة |
| InstalledProducts | المنتجات المثبتة عبر السجل |
| InterestingFiles | الملفات "المثيرة للاهتمام" المطابقة لأنماط مختلفة في مجلد المستخدم. ملاحظة: يستغرق وقتًا غير تافه. |
| LogonEvents | أحداث تسجيل الدخول (معرف الحدث 4624) من سجل الأحداث الأمني. افتراضي 10 أيام، الوسيطة == آخر X أيام. |
| LOLBAS | تحديد موقع ثنائيات ونصوص العيش خارج الأرض (LOLBAS) على النظام. ملاحظة: يستغرق وقتًا غير تافه. |
| McAfeeSiteList | فك تشفير أي ملفات تكوين McAfee SiteList.xml موجودة. |
| MicrosoftUpdates | جميع تحديثات Microsoft (عبر COM) |
| OutlookDownloads | يسرد الملفات التي تم تنزيلها بواسطة Outlook |
| PowerShellEvents | سجلات كتلة سكربت PowerShell (4104) مع بيانات حساسة. |
| Printers | الطابعات المثبتة (عبر WMI) |
| ProcessCreationEvents | سجلات إنشاء العملية (4688) مع بيانات حساسة. |
| ProcessOwners | قائمة العمليات الجارية خارج الجلسة 0 مع المالكين. للاستخدام عن بُعد. |
| RecycleBin | العناصر الموجودة في سلة المحذوفات التي تم حذفها في آخر 30 يومًا - يعمل فقط من سياق المستخدم! |
| reg | قيم مفتاح السجل (HKLM\Software افتراضيًا) الوسيطة == [Path] [intDepth] [Regex] [boolIgnoreErrors] |
| RPCMappedEndpoints | نقاط نهاية RPC الحالية المعينة |
| ScheduledTasks | المهام المجدولة (عبر WMI) التي لم يتم إنشاؤها بواسطة 'Microsoft'، "full" يعرض جميع المهام المجدولة |
| SearchIndex | نتائج الاستعلام من فهرس بحث Windows، المصطلح الافتراضي 'password'. (الوسيطة(الوسائط) == \<search path\> \<pattern1,pattern2,...\> |
| SecurityPackages | تعداد حزم الأمان المتاحة حاليًا باستخدام EnumerateSecurityPackagesA() |
| SysmonEvents | سجلات إنشاء عملية Sysmon (1) مع بيانات حساسة. |
### مجموعات الأوامر الإضافية
يتم تنفيذها باستخدام: `Seatbelt.exe -group=GROUPNAME`
| الاسم المستعار | الوصف |
| ----------- | ----------- |
| Slack | تشغيل الوحدات التي تبدأ بـ "Slack*" |
| Chromium | تشغيل الوحدات التي تبدأ بـ "Chromium*" |
| Remote | تشغيل الوحدات التالية (لاستخدامها ضد نظام بعيد): AMSIProviders, AntiVirus, AuditPolicyRegistry, ChromiumPresence, CloudCredentials, DNSCache, DotNet, DpapiMasterKeys, EnvironmentVariables, ExplicitLogonEvents, ExplorerRunCommands, FileZilla, Hotfixes, InterestingProcesses, KeePass, LastShutdown, LocalGroups, LocalUsers, LogonEvents, LogonSessions, LSASettings, MappedDrives, NetworkProfiles, NetworkShares, NTLMSettings, OptionalFeatures, OSInfo, PoweredOnEvents, PowerShell, ProcessOwners, PSSessionSettings, PuttyHostKeys, PuttySessions, RDPSavedConnections, RDPSessions, RDPsettings, Sysmon, WindowsDefender, WindowsEventForwarding, WindowsFirewall |
## وسائط الأوامر
الأوامر التي تقبل وسائط مذكورة في وصفها. لتمرير وسيطة إلى أمر، قم بإحاطة الأمر والوسائط بين علامتي اقتباس مزدوجتين.
على سبيل المثال، الأمر التالي يعيد أحداث تسجيل الدخول 4624 لآخر 30 يومًا:
`Seatbelt.exe "LogonEvents 30"`
الأمر التالي يستعلم سجلًا بعمق ثلاثة مستويات، ويعيد فقط المفاتيح/أسماء القيم/القيم التي تطابق التعبير العادي `.*defini.*`، ويتجاهل أي أخطاء تحدث.
`Seatbelt.exe "reg \"HKLM\SOFTWARE\Microsoft\Windows Defender\" 3 .*defini.* true"`
## المخرجات
يمكن لـ Seatbelt توجيه مخرجاته إلى ملف باستخدام الوسيطة `-outputfile="C:\Path\file.txt"`. إذا انتهى مسار الملف بـ .json، ستكون المخرجات بصيغة JSON منظمة.
على سبيل المثال، الأمر التالي سيخرج نتائج فحوصات النظام إلى ملف txt:
`Seatbelt.exe -group=system -outputfile="C:\Temp\system.txt"`
## التعداد عن بُعد
الأوامر المذكورة بعلامة + في قائمة المساعدة يمكن تشغيلها عن بُعد ضد نظام آخر. يتم ذلك عبر WMI من خلال استعلامات لفئات WMI و StdRegProv الخاص بـ WMI لتعداد السجل.
لتعداد نظام بعيد، قم بتزويد `-computername=COMPUTER.DOMAIN.COM` - يمكن تحديد اسم مستخدم وكلمة مرور بديلين باستخدام `-username=DOMAIN\USER -password=PASSWORD`
على سبيل المثال، الأمر التالي يقوم بتشغيل فحوصات موجهة عن بُعد ضد نظام بعيد:
`Seatbelt.exe -group=remote -computername=192.168.230.209 -username=THESHIRE\sam -password="yum \"po-ta-toes\""`
## بناء وحداتك الخاصة
هيكل Seatbelt معياري بالكامل، مما يسمح بإضافة وحدات أوامر إضافية إلى هيكل الملف وتحميلها ديناميكيًا.
يوجد قالب وحدة أوامر مع التعليقات في `.\Seatbelt\Commands\Template.cs` كمرجع. بعد البناء، قم بإسقاط الوحدة في موقع الملف المنطقي، وقم بتضمينها في المشروع في مستكشف حلول Visual Studio، ثم قم بتجميع.
## تعليمات التجميع
نحن لا نخطط لإصدار ملفات ثنائية لـ Seatbelt، لذا سيتعين عليك التجميع بنفسك.
تم بناء Seatbelt على .NET 3.5 و 4.0 مع ميزات C# 8.0 وهو متوافق مع [Visual Studio Community Edition](https://visualstudio.microsoft.com/downloads/). ببساطة افتح ملف المشروع .sln، اختر "release"، وقم بالبناء. لتغيير إصدار .NET Framework المستهدف، [قم بتعديل إعدادات المشروع](https://github.com/GhostPack/Seatbelt/issues/27) وأعد بناء المشروع.
## الاعترافات
يحتوي Seatbelt على عناصر جمع متنوعة، وأجزاء من أكواد C#، وأجزاء من براهين المفهوم (PoCs) الموجودة في الأبحاث لقدراته. يتم توضيح هذه الأفكار والأجزاء والمؤلفين في المواقع المناسبة في الكود المصدري، وتشمل:* سكريبت [@andrewchiles](https://twitter.com/andrewchiles)' [HostEnum.ps1](https://github.com/threatexpress/red-team-scripts/blob/master/HostEnum.ps1) وسكريبت [@tifkin\_](https://twitter.com/tifkin_)'s [Get-HostProfile.ps1](https://github.com/leechristensen/Random/blob/master/PowerShellScripts/Get-HostProfile.ps1) كانا مصدر إلهام لكثير من القطع الأثرية التي تم جمعها.
* كود [Boboes' code concerning NetLocalGroupGetMembers](https://stackoverflow.com/questions/33935825/pinvoke-netlocalgroupgetmembers-runs-into-fatalexecutionengineerror/33939889#33939889)
* كود [ambyte's code for converting a mapped drive letter to a network path](https://gist.github.com/ambyte/01664dc7ee576f69042c)
* كود [Igor Korkhov's code to retrieve current token group information](https://stackoverflow.com/questions/2146153/how-to-get-the-logon-sid-in-c-sharp/2146418#2146418)
* مقتطف [RobSiklos' snippet to determine if a host is a virtual machine](https://stackoverflow.com/questions/498371/how-to-detect-if-my-application-is-running-in-a-virtual-machine/11145280#11145280)
* مقتطف [JGU's snippet on file/folder ACL right comparison](https://stackoverflow.com/questions/1410127/c-sharp-test-if-user-has-write-access-to-a-folder/21996345#21996345)
* نمط [Rod Stephens' pattern for recursive file enumeration](http://csharphelper.com/blog/2015/06/find-files-that-match-multiple-patterns-in-c/)
* مقتطف [SwDevMan81's snippet for enumerating current token privileges](https://stackoverflow.com/questions/4349743/setting-size-of-token-privileges-luid-and-attributes-array-returned-by-gettokeni)
* عمل [Jared Atkinson's PowerShell work on Kerberos ticket caches](https://github.com/Invoke-IR/ACE/blob/master/ACE-Management/PS-ACE/Scripts/ACE_Get-KerberosTicketCache.ps1)
* مقتطف [darkmatter08's Kerberos C# snippet](https://www.dreamincode.net/forums/topic/135033-increment-memory-pointer-issue/)
* العديد من نماذج [PInvoke.net](https://www.pinvoke.net/) <3
* مشروع [Jared Hill's awesome CodeProject to use Local Security Authority to Enumerate User Sessions](https://www.codeproject.com/Articles/18179/Using-the-Local-Security-Authority-to-Enumerate-Us)
* كود [Fred's code on querying the ARP cache](https://social.technet.microsoft.com/Forums/lync/en-US/e949b8d6-17ad-4afc-88cd-0019a3ac9df9/powershell-alternative-to-arp-a?forum=ITCG)
* مقتطف [ShuggyCoUk's snippet on querying the TCP connection table](https://stackoverflow.com/questions/577433/which-pid-listens-on-a-given-port-in-c-sharp/577660#577660)
* مثال [yizhang82's example of using reflection to interact with COM objects through C#](https://gist.github.com/yizhang82/a1268d3ea7295a8a1496e01d60ada816)
* مشروع [@djhohnstein](https://twitter.com/djhohnstein)'s [SharpWeb project](https://github.com/djhohnstein/SharpWeb/blob/master/Edge/SharpEdge.cs)
* مشروع [@djhohnstein](https://twitter.com/djhohnstein)'s [EventLogParser project](https://github.com/djhohnstein/EventLogParser)
* مشروع [@cmaddalena](https://twitter.com/cmaddalena)'s [SharpCloud project](https://github.com/chrismaddalena/SharpCloud)، رخصة BSD 3-Clause
* مشروع [@_RastaMouse](https://twitter.com/_RastaMouse)'s [Watson project](https://github.com/rasta-mouse/Watson/)، رخصة GPL
* عمل [@_RastaMouse](https://twitter.com/_RastaMouse)'s [Work on AppLocker enumeration](https://rastamouse.me/2018/09/enumerating-applocker-config/)
* مشروع [@peewpw](https://twitter.com/peewpw)'s [Invoke-WCMDump project](https://github.com/peewpw/Invoke-WCMDump/blob/master/Invoke-WCMDump.ps1)، رخصة GPL
* مشروع TrustedSec's [HoneyBadger project](https://github.com/trustedsec/HoneyBadger/tree/master/modules/post/windows/gather)، رخصة BSD 3-Clause
* مشروع CENTRAL Solutions's [Audit User Rights Assignment Project](https://www.centrel-solutions.com/support/tools.aspx?feature=auditrights)، بدون رخصة
* أفكار جمع مستوحاة من مشروع [@ukstufus](https://twitter.com/ukstufus)'s [Reconerator](https://github.com/stufus/reconerator)
* معلومات مواقع MRU الخاصة بـ Office وتحليل الطوابع الزمنية من ورقة Dustin Hurlbut [Microsoft Office 2007, 2010 - Registry Artifacts](https://ad-pdf.s3.amazonaws.com/Microsoft_Office_2007-2010_Registry_ArtifactsFINAL.pdf)
* قائمة [Windows Commands list](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/windows-commands)، المستخدمة لبناء تعبيرات حساسة منتظمة
* كود [Ryan Ries' code for enumeration mapped RPC endpoints](https://stackoverflow.com/questions/21805038/how-do-i-pinvoke-rpcmgmtepeltinqnext)
* منشور [Chris Haas' post on EnumerateSecurityPackages()](https://stackoverflow.com/a/5941873)
* عمل [darkoperator](https://github.com/ghostpack/seatbelt/blob/HEAD/carlos_perez)'s [on the HoneyBadger project](https://github.com/trustedsec/HoneyBadger)
* عمل [@airzero24](https://twitter.com/airzero24)'s [WMI Registry enumeration](https://github.com/airzero24/WMIReg)
* إجابة Alexandru حول [RegistryKey.OpenBaseKey alternatives](https://stackoverflow.com/questions/26217199/what-are-some-alternatives-to-registrykey-openbasekey-in-net-3-5)
* منشور Tomas Vera [post on JavaScriptSerializer](http://www.tomasvera.com/programming/using-javascriptserializer-to-parse-json-objects/)
* ملاحظة Marc Gravell [note on recursively listing files/folders](https://stackoverflow.com/a/929418)
* محلل [@mattifestation](https://twitter.com/mattifestation)'s [Sysmon rule parser](https://github.com/mattifestation/PSSysmonTools/blob/master/PSSysmonTools/Code/SysmonRuleParser.ps1#L589-L595)
* بعض الإلهام من مشروع spolnik [Simple.CredentialsManager project](https://github.com/spolnik/Simple.CredentialsManager)، رخصة Apache 2
* [This post on Credential Guard settings](https://www.tenforums.com/tutorials/68926-verify-if-device-guard-enabled-disabled-windows-10-a.html)
* [This thread](https://social.technet.microsoft.com/Forums/windows/en-US/b0e13a16-51a6-4aca-8d44-c85e097f882b/nametype-in-nla-information-for-a-network-profile) حول معلومات ملف تعريف الشبكة
* منشور Mark McKinnon حول [decoding the DateCreated and DateLastConnected SSID values](http://cfed-ttf.blogspot.com/2009/08/decoding-datecreated-and.html)
* منشور Specops [post on group policy caching](https://specopssoft.com/blog/things-work-group-policy-caching/)
* منشور sa_ddam213 على StackOverflow حول [enumerating items in the Recycle Bin](https://stackoverflow.com/questions/18071412/list-filenames-in-the-recyclebin-with-c-sharp-without-using-any-external-files)
* كود Kirill Osenkov [code for managed assembly detection](https://stackoverflow.com/a/15608028)
* مشروع [Mono project](https://github.com/mono/linux-packaging-mono/blob/d356d2b7db91d62b80a61eeb6fbc70a402ac3cac/external/corefx/LICENSE.TXT) لصفوف SecBuffer/SecBufferDesc
* [Elad Shamir](https://twitter.com/elad_shamir) ومشروعه [Internal-Monologue](https://github.com/eladshamir/Internal-Monologue/)، و [Vincent Le Toux](https://twitter.com/mysmartlogon) لمشروعه [DetectPasswordViaNTLMInFlow](https://github.com/vletoux/DetectPasswordViaNTLMInFlow/)، و Lee Christensen لمشروع [GetNTLMChallenge](https://github.com/leechristensen/GetNTLMChallenge/). كل هذه كانت مصدر إلهام في أمر SecPackageCreds.
* @leftp و @eksperience مشروع [Gopher project](https://github.com/EncodeGroup/Gopher) لإلهام أوامر FileZilla و SuperPutty
* @funoverip لكود فك تشفير McAfee SiteList.xml الأصلي
لقد حاولنا القيام بواجبنا في الاستشهادات، ولكن إذا أغفلنا أحدًا أو شيئًا، فيرجى إخبارنا!