
Seatbelt एक C# प्रोजेक्ट है जो सुरक्षा-उन्मुख होस्ट-सर्वेक्षण के लिए कई "सुरक्षा जांचें" करता है जो आक्रामक और रक्षात्मक सुरक्षा दृष्टिकोणों से प्रासंगिक हैं।
सीटबेल्ट एक C# प्रोजेक्ट है जो सुरक्षा-उन्मुख होस्ट-सर्वेक्षण "सुरक्षा जांच" करता है जो आक्रामक और रक्षात्मक सुरक्षा दृष्टिकोण से प्रासंगिक हैं।
@andrewchiles' HostEnum.ps1 स्क्रिप्ट और @tifkin_'s Get-HostProfile.ps1 ने कई आर्टिफैक्ट्स को इकट्ठा करने के लिए प्रेरणा प्रदान की।
@harmj0y और @tifkin_ इस कार्यान्वयन के प्रमुख लेखक हैं।
सीटबेल्ट BSD 3-Clause लाइसेंस के तहत लाइसेंस प्राप्त है।
%&&@@@&&
&&&&&&&%%%, #&&@@@@@@%%%%%%###############%
&%& %&%% &////(((&%%%%%#%################//((((###%%%%%%%%%%%%%%%
%%%%%%%%%%%######%%%#%%####% &%%**# @////(((&%%%%%%######################(((((((((((((((((((
#%#%%%%%%%#######%#%%####### %&%,,,,,,,,,,,,,,,, @////(((&%%%%%#%#####################(((((((((((((((((((
#%#%%%%%%#####%%#%#%%####### %%%,,,,,, ,,. ,, @////(((&%%%%%%%######################(#(((#(#((((((((((
#####%%%#################### &%%...... ... .. @////(((&%%%%%%%###############%######((#(#(####((((((((
#######%##########%######### %%%...... ... .. @////(((&%%%%%#########################(#(#######((#####
###%##%%#################### &%%............... @////(((&%%%%%%%%##############%#######(#########((#####
#####%###################### %%%.. @////(((&%%%%%%%################
&%& %%%%% Seatbelt %////(((&%%%%%%%%#############*
&%%&&&%%%%% v1.2.1 ,(((&%%%%%%%%%%%%%%%%%,
#%%%%##,
Available commands (+ means remote usage is supported):
+ AMSIProviders - Providers registered for AMSI
+ AntiVirus - Registered antivirus (via WMI)
+ AppLocker - AppLocker settings, if installed
ARPTable - Lists the current ARP table and adapter information (equivalent to arp -a)
AuditPolicies - Enumerates classic and advanced audit policy settings
+ AuditPolicyRegistry - Audit settings via the registry
+ AutoRuns - Auto run executables/scripts/programs
azuread - Return AzureAD info
Certificates - Finds user and machine personal certificate files
CertificateThumbprints - Finds thumbprints for all certificate store certs on the system
+ ChromiumBookmarks - Parses any found Chrome/Edge/Brave/Opera bookmark files
+ ChromiumHistory - Parses any found Chrome/Edge/Brave/Opera history files
+ ChromiumPresence - Checks if interesting Chrome/Edge/Brave/Opera files exist
+ CloudCredentials - AWS/Google/Azure/Bluemix cloud credential files
+ CloudSyncProviders - All configured Office 365 endpoints (tenants and teamsites) which are synchronised by OneDrive.
CredEnum - Enumerates the current user's saved credentials using CredEnumerate()
+ CredGuard - CredentialGuard configuration
dir - Lists files/folders. By default, lists users' downloads, documents, and desktop folders (arguments == [directory] [maxDepth] [regex] [boolIgnoreErrors]
+ DNSCache - DNS cache entries (via WMI)
+ DotNet - DotNet versions
+ DpapiMasterKeys - List DPAPI master keys
EnvironmentPath - Current environment %PATH$ folders and SDDL information
+ EnvironmentVariables - Current environment variables
+ ExplicitLogonEvents - Explicit Logon events (Event ID 4648) from the security event log. Default of 7 days, argument == last X days.
ExplorerMRUs - Explorer most recently used files (last 7 days, argument == last X days)
+ ExplorerRunCommands - Recent Explorer "run" commands
FileInfo - Information about a file (version information, timestamps, basic PE info, etc. argument(s) == file path(s)
+ FileZilla - FileZilla configuration files
+ FirefoxHistory - Parses any found FireFox history files
+ FirefoxPresence - Checks if interesting Firefox files exist
+ Hotfixes - Installed hotfixes (via WMI)
IdleTime - Returns the number of seconds since the current user's last input.
+ IEFavorites - Internet Explorer favorites
IETabs - Open Internet Explorer tabs
+ IEUrls - Internet Explorer typed URLs (last 7 days, argument == last X days)
+ InstalledProducts - Installed products via the registry
InterestingFiles - "Interesting" files matching various patterns in the user's folder. Note: takes non-trivial time.
+ InterestingProcesses - "Interesting" processes - defensive products and admin tools
InternetSettings - Internet settings including proxy configs and zones configuration
+ KeePass - Finds KeePass configuration files
+ LAPS - LAPS settings, if installed
+ LastShutdown - Returns the DateTime of the last system shutdown (via the registry).
LocalGPOs - Local Group Policy settings applied to the machine/local users
+ LocalGroups - Non-empty local groups, "-full" displays all groups (argument == computername to enumerate)
+ LocalUsers - Local users, whether they're active/disabled, and pwd last set (argument == computername to enumerate)
+ LogonEvents - Logon events (Event ID 4624) from the security event log. Default of 10 days, argument == last X days.
+ LogonSessions - Windows logon sessions
LOLBAS - Locates Living Off The Land Binaries and Scripts (LOLBAS) on the system. Note: takes non-trivial time.
+ LSASettings - LSA settings (including auth packages)
+ MappedDrives - Users' mapped drives (via WMI)
McAfeeConfigs - Finds McAfee configuration files
McAfeeSiteList - Decrypt any found McAfee SiteList.xml configuration files.
MicrosoftUpdates - All Microsoft updates (via COM)
MTPuTTY - MTPuTTY configuration files
NamedPipes - Named pipe names, any readable ACL information and associated process information.
+ NetworkProfiles - Windows network profiles
+ NetworkShares - Network shares exposed by the machine (via WMI)
+ NTLMSettings - NTLM authentication settings
OfficeMRUs - Office most recently used file list (last 7 days)
OneNote - List OneNote backup files
+ OptionalFeatures - List Optional Features/Roles (via WMI)
OracleSQLDeveloper - Finds Oracle SQLDeveloper connections.xml files
+ OSInfo - Basic OS info (i.e. architecture, OS version, etc.)
+ OutlookDownloads - List files downloaded by Outlook
+ PoweredOnEvents - Reboot and sleep schedule based on the System event log EIDs 1, 12, 13, 42, and 6008. Default of 7 days, argument == last X days.
+ PowerShell - PowerShell versions and security settings
+ PowerShellEvents - PowerShell script block logs (4104) with sensitive data.
+ PowerShellHistory - Searches PowerShell console history files for sensitive regex matches.
Printers - Installed Printers (via WMI)
+ ProcessCreationEvents - Process creation logs (4688) with sensitive data.
Processes - Running processes with file info company names that don't contain 'Microsoft', "-full" enumerates all processes
+ ProcessOwners - Running non-session 0 process list with owners. For remote use.
+ PSSessionSettings - Enumerates PS Session Settings from the registry
+ PuttyHostKeys - Saved Putty SSH host keys
+ PuttySessions - Saved Putty configuration (interesting fields) and SSH host keys
RDCManFiles - Windows Remote Desktop Connection Manager settings files
+ RDPSavedConnections - Saved RDP connections stored in the registry
+ RDPSessions - Current incoming RDP sessions (argument == computername to enumerate)
+ RDPsettings - Remote Desktop Server/Client Settings
RecycleBin - Items in the Recycle Bin deleted in the last 30 days - only works from a user context!
reg - Registry key values (HKLM\Software by default) argument == [Path] [intDepth] [Regex] [boolIgnoreErrors]
RPCMappedEndpoints - Current RPC endpoints mapped
+ SCCM - System Center Configuration Manager (SCCM) settings, if applicable
+ ScheduledTasks - Scheduled tasks (via WMI) that aren't authored by 'Microsoft', "-full" dumps all Scheduled tasks
SearchIndex - Query results from the Windows Search Index, default term of 'passsword'. (argument(s) == <search path> <pattern1,pattern2,...>
SecPackageCreds - Obtains credentials from security packages
+ SecureBoot - Secure Boot configuration
SecurityPackages - Enumerates the security packages currently available using EnumerateSecurityPackagesA()
Services - Services with file info company names that don't contain 'Microsoft', "-full" dumps all processes
+ SlackDownloads - Parses any found 'slack-downloads' files
+ SlackPresence - Checks if interesting Slack files exist
+ SlackWorkspaces - Parses any found 'slack-workspaces' files
+ SuperPutty - SuperPutty configuration files
+ Sysmon - Sysmon configuration from the registry
+ SysmonEvents - Sysmon process creation logs (1) with sensitive data.
TcpConnections - Current TCP connections and their associated processes and services
TokenGroups - The current token's local and domain groups
TokenPrivileges - Currently enabled token privileges (e.g. SeDebugPrivilege/etc.)
+ UAC - UAC system policies via the registry
UdpConnections - Current UDP connections and associated processes and services
UserRightAssignments - Configured User Right Assignments (e.g. SeDenyNetworkLogonRight, SeShutdownPrivilege, etc.) argument == computername to enumerate
WifiProfile - Enumerates the saved Wifi profiles and extract the ssid, authentication type, cleartext key/passphrase (when possible)
+ WindowsAutoLogon - Registry autologon information
WindowsCredentialFiles - Windows credential DPAPI blobs
+ WindowsDefender - Windows Defender settings (including exclusion locations)
+ WindowsEventForwarding - Windows Event Forwarding (WEF) settings via the registry
+ WindowsFirewall - Non-standard firewall rules, "-full" dumps all (arguments == allow/deny/tcp/udp/in/out/domain/private/public)
WindowsVault - Credentials saved in the Windows Vault (i.e. logins from Internet Explorer and Edge).
+ WMI - Runs a specified WMI query
WMIEventConsumer - Lists WMI Event Consumers
WMIEventFilter - Lists WMI Event Filters
WMIFilterBinding - Lists WMI Filter to Consumer Bindings
+ WSUS - Windows Server Update Services (WSUS) settings, if applicable
Seatbelt has the following command groups: All, User, System, Slack, Chromium, Remote, Misc
You can invoke command groups with "Seatbelt.exe <group>"
Or command groups except specific commands "Seatbelt.exe <group> -Command"
"Seatbelt.exe -group=all" runs all commands
"Seatbelt.exe -group=user" runs the following commands:
azuread, Certificates, CertificateThumbprints, ChromiumPresence, CloudCredentials,
CloudSyncProviders, CredEnum, dir, DpapiMasterKeys,
ExplorerMRUs, ExplorerRunCommands, FileZilla, FirefoxPresence,
IdleTime, IEFavorites, IETabs, IEUrls,
KeePass, MappedDrives, MTPuTTY, OfficeMRUs,
OneNote, OracleSQLDeveloper, PowerShellHistory, PuttyHostKeys,
PuttySessions, RDCManFiles, RDPSavedConnections, SecPackageCreds,
SlackDownloads, SlackPresence, SlackWorkspaces, SuperPutty,
TokenGroups, WindowsCredentialFiles, WindowsVault
"Seatbelt.exe -group=system" runs the following commands:
AMSIProviders, AntiVirus, AppLocker, ARPTable, AuditPolicies,
AuditPolicyRegistry, AutoRuns, Certificates, CertificateThumbprints,
CredGuard, DNSCache, DotNet, EnvironmentPath,
EnvironmentVariables, Hotfixes, InterestingProcesses, InternetSettings,
LAPS, LastShutdown, LocalGPOs, LocalGroups,
LocalUsers, LogonSessions, LSASettings, McAfeeConfigs,
NamedPipes, NetworkProfiles, NetworkShares, NTLMSettings,
OptionalFeatures, OSInfo, PoweredOnEvents, PowerShell,
Processes, PSSessionSettings, RDPSessions, RDPsettings,
SCCM, SecureBoot, Services, Sysmon,
TcpConnections, TokenPrivileges, UAC, UdpConnections,
UserRightAssignments, WifiProfile, WindowsAutoLogon, WindowsDefender,
WindowsEventForwarding, WindowsFirewall, WMI, WMIEventConsumer,
WMIEventFilter, WMIFilterBinding, WSUS
"Seatbelt.exe -group=slack" runs the following commands:
SlackDownloads, SlackPresence, SlackWorkspaces
"Seatbelt.exe -group=chromium" runs the following commands:
ChromiumBookmarks, ChromiumHistory, ChromiumPresence
"Seatbelt.exe -group=remote" runs the following commands:
AMSIProviders, AntiVirus, AuditPolicyRegistry, ChromiumPresence, CloudCredentials,
DNSCache, DotNet, DpapiMasterKeys, EnvironmentVariables,
ExplicitLogonEvents, ExplorerRunCommands, FileZilla, Hotfixes,
InterestingProcesses, KeePass, LastShutdown, LocalGroups,
LocalUsers, LogonEvents, LogonSessions, LSASettings,
MappedDrives, NetworkProfiles, NetworkShares, NTLMSettings,
OptionalFeatures, OSInfo, PoweredOnEvents, PowerShell,
ProcessOwners, PSSessionSettings, PuttyHostKeys, PuttySessions,
RDPSavedConnections, RDPSessions, RDPsettings, SecureBoot,
Sysmon, WindowsDefender, WindowsEventForwarding, WindowsFirewall
"Seatbelt.exe -group=misc" runs the following commands:
ChromiumBookmarks, ChromiumHistory, ExplicitLogonEvents, FileInfo, FirefoxHistory,
InstalledProducts, InterestingFiles, LogonEvents, LOLBAS,
McAfeeSiteList, MicrosoftUpdates, OutlookDownloads, PowerShellEvents,
Printers, ProcessCreationEvents, ProcessOwners, RecycleBin,
reg, RPCMappedEndpoints, ScheduledTasks, SearchIndex,
SecurityPackages, SysmonEvents
Examples: 'Seatbelt.exe [Command2] ...' will run one or more specified checks only 'Seatbelt.exe -full' will return complete results for a command without any filtering. 'Seatbelt.exe " [argument]"' will pass an argument to a command that supports it (note the quotes). 'Seatbelt.exe -group=all' will run ALL enumeration checks, can be combined with "-full". 'Seatbelt.exe -group=all -AuditPolicies' will run all enumeration checks EXCEPT AuditPolicies, can be combined with "-full". 'Seatbelt.exe -computername=COMPUTER.DOMAIN.COM [-username=DOMAIN\USER -password=PASSWORD]' will run an applicable check remotely 'Seatbelt.exe -group=remote -computername=COMPUTER.DOMAIN.COM [-username=DOMAIN\USER -password=PASSWORD]' will run remote specific checks 'Seatbelt.exe -group=system -outputfile="C:\Temp\out.txt"' will run system checks and output to a .txt file. 'Seatbelt.exe -group=user -q -outputfile="C:\Temp\out.json"' will run in quiet mode with user checks and output to a .json file.
**ध्यान दें:** उपयोगकर्ताओं को लक्षित करने वाली खोजें वर्तमान उपयोगकर्ता के लिए चलेंगी यदि ऊँचा नहीं किया गया है और सभी उपयोगकर्ताओं के लिए यदि ऊँचा किया गया है।
## कमांड ग्रुप
**ध्यान दें:** कई कमांड डिफ़ॉल्ट रूप से किसी प्रकार का फ़िल्टरिंग करते हैं। `-full` आर्गुमेंट प्रदान करने से आउटपुट को फ़िल्टर होने से रोका जाता है। साथ ही, कमांड ग्रुप `all` सभी वर्तमान जाँचें चलाएगा।
उदाहरण के लिए, निम्न कमांड सभी जाँचें चलाएगा और सभी आउटपुट लौटाएगा:
`Seatbelt.exe -group=all -full`
### system
वे जाँचें चलाता है जो सिस्टम के बारे में दिलचस्प डेटा निकालती हैं।
इसके साथ निष्पादित किया गया: `Seatbelt.exe -group=system`
| कमांड | विवरण |
| ----------- | ----------- |
| AMSIProviders | AMSI के लिए पंजीकृत प्रदाता |
| AntiVirus | पंजीकृत एंटीवायरस (WMI के माध्यम से) |
| AppLocker | AppLocker सेटिंग्स, यदि स्थापित है |
| ARPTable | वर्तमान ARP तालिका और एडाप्टर जानकारी सूचीबद्ध करता है (arp -a के समतुल्य) |
| AuditPolicies | क्लासिक और उन्नत ऑडिट नीति सेटिंग्स की गणना करता है |
| AuditPolicyRegistry | रजिस्ट्री के माध्यम से ऑडिट सेटिंग्स |
| AutoRuns | ऑटो रन एक्ज़ीक्यूटेबल/स्क्रिप्ट/प्रोग्राम |
| Certificates | उपयोगकर्ता और मशीन के व्यक्तिगत प्रमाणपत्र फ़ाइलें |
| CertificateThumbprints | सिस्टम पर सभी प्रमाणपत्र स्टोर प्रमाणपत्रों के लिए थंबप्रिंट |
| CredGuard | CredentialGuard कॉन्फ़िगरेशन |
| DNSCache | DNS कैैश प्रविष्टियाँ (WMI के माध्यम से) |
| DotNet | DotNet संस्करण |
| EnvironmentPath | वर्तमान वातावरण %PATH$ फ़ोल्डर और SDDL जानकारी |
| EnvironmentVariables | वर्तमान उपयोगकर्ता पर्यावरण चर |
| Hotfixes | स्थापित हॉटफिक्स (WMI के माध्यम से) |
| InterestingProcesses | "दिलचस्प" प्रक्रियाएँ - रक्षात्मक उत्पाद और प्रशासन उपकरण |
| InternetSettings | प्रॉक्सी कॉन्फ़िग सहित इंटरनेट सेटिंग्स |
| LAPS | LAPS सेटिंग्स, यदि स्थापित है |
| LastShutdown | अंतिम सिस्टम शटडाउन का DateTime लौटाता है (रजिस्ट्री के माध्यम से) |
| LocalGPOs | मशीन/स्थानीय उपयोगकर्ताओं पर लागू स्थानीय समूह नीति सेटिंग्स |
| LocalGroups | गैर-रिक्त स्थानीय समूह, "पूर्ण" सभी समूह प्रदर्शित करता है (आर्गुमेंट == गणना करने के लिए कंप्यूटरनाम) |
| LocalUsers | स्थानीय उपयोगकर्ता, वे सक्रिय/अक्षम हैं या नहीं, और pwd अंतिम बार सेट किया गया (आर्गुमेंट == गणना करने के लिए कंप्यूटरनाम) |
| LogonSessions | सुरक्षा इवेंट लॉग से लॉगऑन इवेंट (इवेंट आईडी 4624)। डिफ़ॉल्ट 10 दिन, आर्गुमेंट == पिछले X दिन। |
| LSASettings | LSA सेटिंग्स (प्रमाणीकरण पैकेज सहित) |
| McAfeeConfigs | McAfee कॉन्फ़िगरेशन फ़ाइलें ढूँढता है |
| NamedPipes | नामित पाइप नाम और कोई भी पढ़ने योग्य ACL जानकारी |
| NetworkProfiles | विंडोज़ नेटवर्क प्रोफ़ाइल |
| NetworkShares | मशीन द्वारा उजागर नेटवर्क शेयर (WMI के माध्यम से) |
| NTLMSettings | NTLM प्रमाणीकरण सेटिंग्स |
| OptionalFeatures | TODO |
| OSInfo | बुनियादी OS जानकारी (जैसे आर्किटेक्चर, OS संस्करण, आदि) |
| PoweredOnEvents | सिस्टम इवेंट लॉग EIDs 1, 12, 13, 42, और 6008 के आधार पर रीबूट और स्लीप शेड्यूल। डिफ़ॉल्ट 7 दिन, आर्गुमेंट == पिछले X दिन। |
| PowerShell | PowerShell संस्करण और सुरक्षा सेटिंग्स |
| Processes | चल रही प्रक्रियाएँ जिनमें फ़ाइल जानकारी कंपनी के नाम हैं जिनमें 'Microsoft' नहीं है, "पूर्ण" सभी प्रक्रियाओं की गणना करता है |
| PSSessionSettings | रजिस्ट्री से PS सत्र सेटिंग्स की गणना करता है |
| RDPSessions | वर्तमान आने वाले RDP सत्र (आर्गुमेंट == गणना करने के लिए कंप्यूटरनाम) |
| RDPsettings | रिमोट डेस्कटॉप सर्वर/क्लाइंट सेटिंग्स |
| SCCM | System Center Configuration Manager (SCCM) सेटिंग्स, यदि लागू हो |
| Services | सेवाएँ जिनमें फ़ाइल जानकारी कंपनी के नाम हैं जिनमें 'Microsoft' नहीं है, "पूर्ण" सभी प्रक्रियाओं को डंप करता है |
| Sysmon | रजिस्ट्री से Sysmon कॉन्फ़िगरेशन |
| TcpConnections | वर्तमान TCP कनेक्शन और उनसे जुड़ी प्रक्रियाएँ और सेवाएँ |
| TokenPrivileges | वर्तमान में सक्षम टोकन विशेषाधिकार (जैसे SeDebugPrivilege/etc.) |
| UAC | रजिस्ट्री के माध्यम से UAC सिस्टम नीतियाँ |
| UdpConnections | वर्तमान UDP कनेक्शन और संबंधित प्रक्रियाएँ और सेवाएँ |
| UserRightAssignments | कॉन्फ़िगर किए गए उपयोगकर्ता अधिकार असाइनमेंट (जैसे SeDenyNetworkLogonRight, SeShutdownPrivilege, आदि) आर्गुमेंट == गणना करने के लिए कंप्यूटरनाम |
| WifiProfile | TODO |
| WindowsAutoLogon | रजिस्ट्री ऑटोलॉगऑन जानकारी |
| WindowsDefender | Windows Defender सेटिंग्स (बहिष्करण स्थानों सहित) |
| WindowsEventForwarding | रजिस्ट्री के माध्यम से Windows Event Forwarding (WEF) सेटिंग्स |
| WindowsFirewall | गैर-मानक फ़ायरवॉल नियम, "पूर्ण" सभी को डंप करता है (आर्गुमेंट == allow/deny/tcp/udp/in/out/domain/private/public) |
| WMIEventConsumer | WMI इवेंट उपभोक्ताओं को सूचीबद्ध करता है |
| WMIEventFilter | WMI इवेंट फ़िल्टर को सूचीबद्ध करता है |
| WMIFilterBinding | WMI फ़िल्टर से उपभोक्ता बाइंडिंग को सूचीबद्ध करता है |
| WSUS | Windows Server Update Services (WSUS) सेटिंग्स, यदि लागू हो |
### user
वे जाँचें चलाता है जो वर्तमान में लॉग ऑन उपयोगकर्ता (यदि ऊँचा नहीं किया गया है) या सभी उपयोगकर्ताओं (यदि ऊँचा किया गया है) के बारे में दिलचस्प डेटा निकालती हैं।
इसके साथ निष्पादित किया गया: `Seatbelt.exe -group=user`
| कमांड | विवरण |
| ----------- | ----------- |
| Certificates | उपयोगकर्ता और मशीन के व्यक्तिगत प्रमाणपत्र फ़ाइलें |
| CertificateThumbprints | सिस्टम पर सभी प्रमाणपत्र स्टोर प्रमाणपत्रों के लिए थंबप्रिंट |
| ChromiumPresence | जाँचता है कि क्या दिलचस्प Chrome/Edge/Brave/Opera फ़ाइलें मौजूद हैं |
| CloudCredentials | AWS/Google/Azure क्लाउड क्रेडेंशियल फ़ाइलें |
| CloudSyncProviders | TODO |
| CredEnum | CredEnumerate() का उपयोग करके वर्तमान उपयोगकर्ता के सहेजे गए क्रेडेंशियल्स की गणना करता है |
| dir | फ़ाइलों/फ़ोल्डरों को सूचीबद्ध करता है। डिफ़ॉल्ट रूप से, उपयोगकर्ताओं के डाउनलोड, दस्तावेज़ और डेस्कटॉप फ़ोल्डर सूचीबद्ध करता है (आर्गुमेंट == \<निर्देशिका\> \<गहराई\> \<regex\> |
| DpapiMasterKeys | DPAPI मास्टर कुंजियाँ सूचीबद्ध करता है |
| Dsregcmd | TODO |
| ExplorerMRUs | एक्सप्लोरर हाल ही में उपयोग की गई फ़ाइलें (पिछले 7 दिन, आर्गुमेंट == पिछले X दिन) |
| ExplorerRunCommands | हाल के एक्सप्लोरर "रन" कमांड |
| FileZilla | FileZilla कॉन्फ़िगरेशन फ़ाइलें |
| FirefoxPresence | जाँचता है कि क्या दिलचस्प Firefox फ़ाइलें मौजूद हैं |
| IdleTime | वर्तमान उपयोगकर्ता के अंतिम इनपुट के बाद से सेकंड की संख्या लौटाता है। |
| IEFavorites | Internet Explorer पसंदीदा |
| IETabs | खुले Internet Explorer टैब |
| IEUrls| Internet Explorer द्वारा टाइप किए गए URL (पिछले 7 दिन, आर्गुमेंट == पिछले X दिन) |
| KeePass | TODO |
| MappedDrives | उपयोगकर्ताओं के मैप किए गए ड्राइव (WMI के माध्यम से) |
| OfficeMRUs | Office हाल ही में उपयोग की गई फ़ाइलों की सूची (पिछले 7 दिन) |
| OneNote | TODO |
| OracleSQLDeveloper | TODO |
| PowerShellHistory | प्रत्येक स्थानीय उपयोगकर्ता के माध्यम से पुनरावृति करता है और उनके PowerShell कंसोल इतिहास को पढ़ने का प्रयास करता है यदि सफल होता है तो इसे प्रिंट करेगा |
| PuttyHostKeys | सहेजी गई Putty SSH होस्ट कुंजियाँ |
| PuttySessions | सहेजी गई Putty कॉन्फ़िगरेशन (दिलचस्प फ़ील्ड) और SSH होस्ट कुंजियाँ |
| RDCManFiles | Windows Remote Desktop Connection Manager सेटिंग्स फ़ाइलें |
| RDPSavedConnections | रजिस्ट्री में संग्रहीत सहेजे गए RDP कनेक्शन |
| SecPackageCreds | सुरक्षा पैकेजों से क्रेडेंशियल प्राप्त करता है |
| SlackDownloads | किसी भी मिली 'slack-downloads' फ़ाइलों को पार्स करता है |
| SlackPresence | जाँचता है कि क्या दिलचस्प Slack फ़ाइलें मौजूद हैं |
| SlackWorkspaces | किसी भी मिली 'slack-workspaces' फ़ाइलों को पार्स करता है |
| SuperPutty | SuperPutty कॉन्फ़िगरेशन फ़ाइलें |
| TokenGroups | वर्तमान टोकन के स्थानीय और डोमेन समूह |
| WindowsCredentialFiles | Windows क्रेडेंशियल DPAPI ब्लॉब |
| WindowsVault | Windows Vault में सहेजे गए क्रेडेंशियल्स (अर्थात Internet Explorer और Edge से लॉगिन)। |
### misc
सभी विविध जाँचें चलाता है।
इसके साथ निष्पादित किया गया: `Seatbelt.exe -group=misc`
| कमांड | विवरण |
| ----------- | ----------- |
| ChromiumBookmarks | किसी भी मिली Chrome/Edge/Brave/Opera बुकमार्क फ़ाइलों को पार्स करता है |
| ChromiumHistory | किसी भी मिली Chrome/Edge/Brave/Opera इतिहास फ़ाइलों को पार्स करता है |
| ExplicitLogonEvents | सुरक्षा इवेंट लॉग से स्पष्ट लॉगऑन इवेंट (इवेंट आईडी 4648)। डिफ़ॉल्ट 7 दिन, आर्गुमेंट == पिछले X दिन। |
| FileInfo | किसी फ़ाइल के बारे में जानकारी (संस्करण जानकारी, टाइमस्टैम्प, बुनियादी PE जानकारी, आदि। आर्गुमेंट == फ़ाइल पथ |
| FirefoxHistory | किसी भी मिली FireFox इतिहास फ़ाइलों को पार्स करता है |
| InstalledProducts | रजिस्ट्री के माध्यम से स्थापित उत्पाद |
| InterestingFiles | उपयोगकर्ता के फ़ोल्डर में विभिन्न पैटर्न से मेल खाने वाली "दिलचस्प" फ़ाइलें। ध्यान दें: गैर-तुच्छ समय लेता है। |
| LogonEvents | सुरक्षा इवेंट लॉग से लॉगऑन इवेंट (इवेंट आईडी 4624)। डिफ़ॉल्ट 10 दिन, आर्गुमेंट == पिछले X दिन। |
| LOLBAS | सिस्टम पर Living Off The Land Binaries and Scripts (LOLBAS) का पता लगाता है। ध्यान दें: गैर-तुच्छ समय लेता है। |
| McAfeeSiteList | किसी भी मिली McAfee SiteList.xml कॉन्फ़िगरेशन फ़ाइलों को डिक्रिप्ट करें। |
| MicrosoftUpdates | सभी Microsoft अपडेट (COM के माध्यम से) |
| OutlookDownloads | Outlook द्वारा डाउनलोड की गई फ़ाइलों को सूचीबद्ध करता है |
| PowerShellEvents | संवेदनशील डेटा के साथ PowerShell स्क्रिप्ट ब्लॉक लॉग (4104)। |
| Printers | स्थापित प्रिंटर (WMI के माध्यम से) |
| ProcessCreationEvents | संवेदनशील डेटा के साथ प्रक्रिया निर्माण लॉग (4688)। |
| ProcessOwners | मालिकों के साथ चल रही गैर-सत्र 0 प्रक्रिया सूची। रिमोट उपयोग के लिए। |
| RecycleBin | पिछले 30 दिनों में हटाई गई रीसायकल बिन में आइटम - केवल उपयोगकर्ता संदर्भ से काम करता है! |
| reg | रजिस्ट्री कुंजी मान (डिफ़ॉल्ट रूप से HKLM\Software) आर्गुमेंट == [पथ] [intगहराई] [Regex] [boolत्रुटियाँ_अनदेखा करें] |
| RPCMappedEndpoints | वर्तमान RPC एंडपॉइंट मैप किए गए |
| ScheduledTasks | 'Microsoft' द्वारा लेखक नहीं किए गए शेड्यूल किए गए कार्य (WMI के माध्यम से), "पूर्ण" सभी शेड्यूल किए गए कार्यों को डंप करता है |
| SearchIndex | Windows Search Index से क्वेरी परिणाम, डिफ़ॉल्ट शब्द 'passsword'। (आर्गुमेंट(s) == \<खोज पथ\> \<पैटर्न1,पैटर्न2,...\> |
| SecurityPackages | EnumerateSecurityPackagesA() का उपयोग करके वर्तमान में उपलब्ध सुरक्षा पैकेजों की गणना करता है |
| SysmonEvents | संवेदनशील डेटा के साथ Sysmon प्रक्रिया निर्माण लॉग (1)। |
### अतिरिक्त कमांड ग्रुप
इसके साथ निष्पादित किया गया: `Seatbelt.exe -group=GROUPNAME`
| उपनाम | विवरण |
| ----------- | ----------- |
| Slack | "Slack*" से शुरू होने वाले मॉड्यूल चलाता है |
| Chromium | "Chromium*" से शुरू होने वाले मॉड्यूल चलाता है |
| Remote | निम्नलिखित मॉड्यूल चलाता है (रिमोट सिस्टम के खिलाफ उपयोग के लिए): AMSIProviders, AntiVirus, AuditPolicyRegistry, ChromiumPresence, CloudCredentials, DNSCache, DotNet, DpapiMasterKeys, EnvironmentVariables, ExplicitLogonEvents, ExplorerRunCommands, FileZilla, Hotfixes, InterestingProcesses, KeePass, LastShutdown, LocalGroups, LocalUsers, LogonEvents, LogonSessions, LSASettings, MappedDrives, NetworkProfiles, NetworkShares, NTLMSettings, OptionalFeatures, OSInfo, PoweredOnEvents, PowerShell, ProcessOwners, PSSessionSettings, PuttyHostKeys, PuttySessions, RDPSavedConnections, RDPSessions, RDPsettings, Sysmon, WindowsDefender, WindowsEventForwarding, WindowsFirewall |
## कमांड आर्गुमेंट
जो कमांड आर्गुमेंट स्वीकार करते हैं, उनके विवरण में इसका उल्लेख किया गया है। किसी कमांड को आर्गुमेंट पास करने के लिए, कमांड और आर्गुमेंट को डबल कोट्स में बंद करें।
उदाहरण के लिए, निम्न कमांड पिछले 30 दिनों के 4624 लॉगऑन इवेंट लौटाता है:
`Seatbelt.exe "LogonEvents 30"`
निम्न कमांड तीन स्तर गहरी रजिस्ट्री क्वेरी करता है, केवल उन कुंजियों/माननामों/मानों को लौटाता है जो regex `.*defini.*` से मेल खाते हैं, और होने वाली किसी भी त्रुटि को अनदेखा करता है।
`Seatbelt.exe "reg \"HKLM\SOFTWARE\Microsoft\Windows Defender\" 3 .*defini.* true"`
## आउटपुट
Seatbelt अपने आउटपुट को `-outputfile="C:\Path\file.txt"` आर्गुमेंट के साथ एक फ़ाइल में रीडायरेक्ट कर सकता है। यदि फ़ाइल पथ .json में समाप्त होता है, तो आउटपुट संरचित json होगा।
उदाहरण के लिए, निम्न कमांड सिस्टम जाँचों के परिणामों को एक txt फ़ाइल में आउटपुट करेगा:
`Seatbelt.exe -group=system -outputfile="C:\Temp\system.txt"`
## रिमोट एनुमरेशन
हेल्प मेनू में + के साथ नोट किए गए कमांड को किसी अन्य सिस्टम के खिलाफ दूरस्थ रूप से चलाया जा सकता है। यह WMI कक्षाओं के लिए क्वेरी और रजिस्ट्री एनुमरेशन के लिए WMI के StdRegProv के माध्यम से WMI पर किया जाता है।
किसी रिमोट सिस्टम की गणना करने के लिए, `-computername=COMPUTER.DOMAIN.COM` प्रदान करें - एक वैकल्पिक उपयोगकर्ता नाम और पासवर्ड `-username=DOMAIN\USER -password=PASSWORD` के साथ निर्दिष्ट किया जा सकता है
उदाहरण के लिए, निम्न कमांड एक रिमोट सिस्टम के खिलाफ रिमोट-केंद्रित जाँच चलाता है:
`Seatbelt.exe -group=remote -computername=192.168.230.209 -username=THESHIRE\sam -password="yum \"po-ta-toes\""`
## अपने स्वयं के मॉड्यूल बनाना
Seatbelt की संरचना पूरी तरह से मॉड्यूलर है, जो अतिरिक्त कमांड मॉड्यूल को फ़ाइल संरचना में गिराए जाने और गतिशील रूप से लोड होने की अनुमति देती है।
संदर्भ के लिए `.\Seatbelt\Commands\Template.cs` पर एक टिप्पणी सहित कमांड मॉड्यूल टेम्पलेट है। बनने के बाद, मॉड्यूल को तार्किक फ़ाइल स्थान पर रखें, इसे Visual Studio Solution Explorer में प्रोजेक्ट में शामिल करें, और संकलित करें।
## संकलन निर्देश
हम Seatbelt के लिए बाइनरी जारी करने की योजना नहीं बना रहे हैं, इसलिए आपको स्वयं संकलित करना होगा।
Seatbelt C# 8.0 सुविधाओं के साथ .NET 3.5 और 4.0 के खिलाफ बनाया गया है और [Visual Studio Community Edition](https://visualstudio.microsoft.com/downloads/) के साथ संगत है। बस प्रोजेक्ट .sln खोलें, "रिलीज़" चुनें, और बनाएँ। लक्ष्य .NET फ्रेमवर्क संस्करण को बदलने के लिए, [प्रोजेक्ट की सेटिंग्स संशोधित करें](https://github.com/GhostPack/Seatbelt/issues/27) और प्रोजेक्ट को पुनर्निर्माण करें।
## आभार
Seatbelt अपनी क्षमताओं के लिए अनुसंधान के दौरान पाए गए विभिन्न संग्रह आइटम, C# कोड स्निपेट और PoCs के बिट्स को शामिल करता है। ये विचार, स्निपेट और लेखक स्रोत कोड में उपयुक्त स्थानों पर हाइलाइट किए गए हैं, और इसमें शामिल हैं:* [@andrewchiles](https://twitter.com/andrewchiles) का [HostEnum.ps1](https://github.com/threatexpress/red-team-scripts/blob/master/HostEnum.ps1) स्क्रिप्ट और [@tifkin\_](https://twitter.com/tifkin_) का [Get-HostProfile.ps1](https://github.com/leechristensen/Random/blob/master/PowerShellScripts/Get-HostProfile.ps1) ने एकत्रित करने के लिए कई आर्टिफैक्ट्स के लिए प्रेरणा प्रदान की।
* [NetLocalGroupGetMembers से संबंधित Boboes का कोड](https://stackoverflow.com/questions/33935825/pinvoke-netlocalgroupgetmembers-runs-into-fatalexecutionengineerror/33939889#33939889)
* [मैप किए गए ड्राइव अक्षर को नेटवर्क पथ में बदलने के लिए ambyte का कोड](https://gist.github.com/ambyte/01664dc7ee576f69042c)
* [वर्तमान टोकन समूह जानकारी प्राप्त करने के लिए Igor Korkhov का कोड](https://stackoverflow.com/questions/2146153/how-to-get-the-logon-sid-in-c-sharp/2146418#2146418)
* [यह निर्धारित करने के लिए RobSiklos का स्निपेट कि कोई होस्ट वर्चुअल मशीन है या नहीं](https://stackoverflow.com/questions/498371/how-to-detect-if-my-application-is-running-in-a-virtual-machine/11145280#11145280)
* [फ़ाइल/फ़ोल्डर ACL अधिकार तुलना पर JGU का स्निपेट](https://stackoverflow.com/questions/1410127/c-sharp-test-if-user-has-write-access-to-a-folder/21996345#21996345)
* [पुनरावर्ती फ़ाइल गणना के लिए Rod Stephens का पैटर्न](http://csharphelper.com/blog/2015/06/find-files-that-match-multiple-patterns-in-c/)
* [वर्तमान टोकन विशेषाधिकारों की गणना के लिए SwDevMan81 का स्निपेट](https://stackoverflow.com/questions/4349743/setting-size-of-token-privileges-luid-and-attributes-array-returned-by-gettokeni)
* [Kerberos टिकट कैश पर Jared Atkinson का PowerShell कार्य](https://github.com/Invoke-IR/ACE/blob/master/ACE-Management/PS-ACE/Scripts/ACE_Get-KerberosTicketCache.ps1)
* [darkmatter08 का Kerberos C# स्निपेट](https://www.dreamincode.net/forums/topic/135033-increment-memory-pointer-issue/)
* कई [PInvoke.net](https://www.pinvoke.net/) नमूने <3
* [उपयोगकर्ता सत्रों की गणना करने के लिए स्थानीय सुरक्षा प्राधिकरण का उपयोग करने पर Jared Hill का शानदार CodeProject](https://www.codeproject.com/Articles/18179/Using-the-Local-Security-Authority-to-Enumerate-Us)
* [ARP कैश क्वेरी करने पर Fred का कोड](https://social.technet.microsoft.com/Forums/lync/en-US/e949b8d6-17ad-4afc-88cd-0019a3ac9df9/powershell-alternative-to-arp-a?forum=ITCG)
* [TCP कनेक्शन तालिका क्वेरी करने पर ShuggyCoUk का स्निपेट](https://stackoverflow.com/questions/577433/which-pid-listens-on-a-given-port-in-c-sharp/577660#577660)
* [C# के माध्यम से COM ऑब्जेक्ट्स के साथ बातचीत करने के लिए रिफ्लेक्शन का उपयोग करने का yizhang82 का उदाहरण](https://gist.github.com/yizhang82/a1268d3ea7295a8a1496e01d60ada816)
* [@djhohnstein](https://twitter.com/djhohnstein) का [SharpWeb प्रोजेक्ट](https://github.com/djhohnstein/SharpWeb/blob/master/Edge/SharpEdge.cs)
* [@djhohnstein](https://twitter.com/djhohnstein) का [EventLogParser प्रोजेक्ट](https://github.com/djhohnstein/EventLogParser)
* [@cmaddalena](https://twitter.com/cmaddalena) का [SharpCloud प्रोजेक्ट](https://github.com/chrismaddalena/SharpCloud), BSD 3-Clause
* [@_RastaMouse](https://twitter.com/_RastaMouse) का [Watson प्रोजेक्ट](https://github.com/rasta-mouse/Watson/), GPL License
* [@_RastaMouse](https://twitter.com/_RastaMouse) का [AppLocker गणना पर कार्य](https://rastamouse.me/2018/09/enumerating-applocker-config/)
* [@peewpw](https://twitter.com/peewpw) का [Invoke-WCMDump प्रोजेक्ट](https://github.com/peewpw/Invoke-WCMDump/blob/master/Invoke-WCMDump.ps1), GPL License
* TrustedSec का [HoneyBadger प्रोजेक्ट](https://github.com/trustedsec/HoneyBadger/tree/master/modules/post/windows/gather), BSD 3-Clause
* CENTRAL Solutions का [ऑडिट उपयोगकर्ता अधिकार असाइनमेंट प्रोजेक्ट](https://www.centrel-solutions.com/support/tools.aspx?feature=auditrights), No license
* [@ukstufus](https://twitter.com/ukstufus) के [Reconerator](https://github.com/stufus/reconerator) से प्रेरित संग्रह विचार
* Dustin Hurlbut के पेपर [Microsoft Office 2007, 2010 - Registry Artifacts](https://ad-pdf.s3.amazonaws.com/Microsoft_Office_2007-2010_Registry_ArtifactsFINAL.pdf) से Office MRU स्थान और टाइमस्टैम्प पार्सिंग जानकारी
* [Windows कमांड की सूची](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/windows-commands), संवेदनशील regex निर्माण के लिए उपयोग किया गया
* [मैप किए गए RPC एंडपॉइंट्स की गणना के लिए Ryan Ries का कोड](https://stackoverflow.com/questions/21805038/how-do-i-pinvoke-rpcmgmtepeltinqnext)
* [EnumerateSecurityPackages() पर Chris Haas की पोस्ट](https://stackoverflow.com/a/5941873)
* [HoneyBadger प्रोजेक्ट पर darkoperator (carlos_perez) का कार्य](https://github.com/trustedsec/HoneyBadger)
* [WMI रजिस्ट्री गणना पर @airzero24](https://twitter.com/airzero24) का कार्य [WMIReg](https://github.com/airzero24/WMIReg)
* [RegistryKey.OpenBaseKey विकल्पों पर Alexandru का उत्तर](https://stackoverflow.com/questions/26217199/what-are-some-alternatives-to-registrykey-openbasekey-in-net-3-5)
* Tomas Vera की [JavaScriptSerializer पर पोस्ट](http://www.tomasvera.com/programming/using-javascriptserializer-to-parse-json-objects/)
* [पुनरावर्ती रूप से फ़ाइलों/फ़ोल्डरों को सूचीबद्ध करने पर Marc Gravell का नोट](https://stackoverflow.com/a/929418)
* [@mattifestation](https://twitter.com/mattifestation) का [Sysmon नियम पार्सर](https://github.com/mattifestation/PSSysmonTools/blob/master/PSSysmonTools/Code/SysmonRuleParser.ps1#L589-L595)
* spolnik के [Simple.CredentialsManager प्रोजेक्ट](https://github.com/spolnik/Simple.CredentialsManager), Apache 2 लाइसेंस से कुछ प्रेरणा
* [क्रेडेंशियल गार्ड सेटिंग्स पर यह पोस्ट](https://www.tenforums.com/tutorials/68926-verify-if-device-guard-enabled-disabled-windows-10-a.html)
* [नेटवर्क प्रोफ़ाइल जानकारी पर यह थ्रेड](https://social.technet.microsoft.com/Forums/windows/en-US/b0e13a16-51a6-4aca-8d44-c85e097f882b/nametype-in-nla-information-for-a-network-profile)
* Mark McKinnon की [DateCreated और DateLastConnected SSID मानों को डिकोड करने पर पोस्ट](http://cfed-ttf.blogspot.com/2009/08/decoding-datecreated-and.html)
* यह Specops [ग्रुप पॉलिसी कैशिंग पर पोस्ट](https://specopssoft.com/blog/things-work-group-policy-caching/)
* sa_ddam213 का StackOverflow पर [रीसायकल बिन में आइटमों की गणना पर पोस्ट](https://stackoverflow.com/questions/18071412/list-filenames-in-the-recyclebin-with-c-sharp-without-using-any-external-files)
* Kirill Osenkov का [प्रबंधित असेंबली पहचान के लिए कोड](https://stackoverflow.com/a/15608028)
* [Mono प्रोजेक्ट](https://github.com/mono/linux-packaging-mono/blob/d356d2b7db91d62b80a61eeb6fbc70a402ac3cac/external/corefx/LICENSE.TXT) SecBuffer/SecBufferDesc क्लासेस के लिए
* [Elad Shamir](https://twitter.com/elad_shamir) और उनका [Internal-Monologue](https://github.com/eladshamir/Internal-Monologue/) प्रोजेक्ट, [Vincent Le Toux](https://twitter.com/mysmartlogon) उनके [DetectPasswordViaNTLMInFlow](https://github.com/vletoux/DetectPasswordViaNTLMInFlow/) प्रोजेक्ट के लिए, और Lee Christensen इस [GetNTLMChallenge](https://github.com/leechristensen/GetNTLMChallenge/) प्रोजेक्ट के लिए। इन सभी ने SecPackageCreds कमांड में प्रेरणा का काम किया।
* @leftp और @eksperience का [Gopher प्रोजेक्ट](https://github.com/EncodeGroup/Gopher) FileZilla और SuperPutty कमांड के लिए प्रेरणा के रूप में
* @funoverip मूल McAfee SiteList.xml डिक्रिप्शन कोड के लिए
हमने उद्धरणों के लिए अपनी पूरी कोशिश की है, लेकिन अगर हम किसी/कुछ को छोड़ गए हैं, तो कृपया हमें बताएं!