
Seatbeltは、攻撃的および防御的なセキュリティの観点から関連する、セキュリティ指向のホスト調査「安全性チェック」を多数実行するC#プロジェクトです。
Seatbeltは、攻撃的および防御的なセキュリティの観点から関連する、セキュリティ指向のホスト調査「安全確認」を実行するC#プロジェクトです。
@andrewchiles氏のHostEnum.ps1スクリプトと@tifkin_氏のGet-HostProfile.ps1は、収集する多くのアーティファクトのインスピレーションを提供しました。
@harmj0y氏と@tifkin_氏がこの実装の主要な作成者です。
SeatbeltはBSD 3-Clauseライセンスの下でライセンスされています。
%&&@@@&&
&&&&&&&%%%, #&&@@@@@@%%%%%%###############%
&%& %&%% &////(((&%%%%%#%################//((((###%%%%%%%%%%%%%%%
%%%%%%%%%%%######%%%#%%####% &%%**# @////(((&%%%%%%######################(((((((((((((((((((
#%#%%%%%%%#######%#%%####### %&%,,,,,,,,,,,,,,,, @////(((&%%%%%#%#####################(((((((((((((((((((
#%#%%%%%%#####%%#%#%%####### %%%,,,,,, ,,. ,, @////(((&%%%%%%%######################(#(((#(#((((((((((
#####%%%#################### &%%...... ... .. @////(((&%%%%%%%###############%######((#(#(####((((((((
#######%##########%######### %%%...... ... .. @////(((&%%%%%#########################(#(#######((#####
###%##%%#################### &%%............... @////(((&%%%%%%%%##############%#######(#########((#####
#####%###################### %%%.. @////(((&%%%%%%%################
&%& %%%%% Seatbelt %////(((&%%%%%%%%#############*
&%%&&&%%%%% v1.2.1 ,(((&%%%%%%%%%%%%%%%%%,
#%%%%##,
Available commands (+ means remote usage is supported):
+ AMSIProviders - Providers registered for AMSI
+ AntiVirus - Registered antivirus (via WMI)
+ AppLocker - AppLocker settings, if installed
ARPTable - Lists the current ARP table and adapter information (equivalent to arp -a)
AuditPolicies - Enumerates classic and advanced audit policy settings
+ AuditPolicyRegistry - Audit settings via the registry
+ AutoRuns - Auto run executables/scripts/programs
azuread - Return AzureAD info
Certificates - Finds user and machine personal certificate files
CertificateThumbprints - Finds thumbprints for all certificate store certs on the system
+ ChromiumBookmarks - Parses any found Chrome/Edge/Brave/Opera bookmark files
+ ChromiumHistory - Parses any found Chrome/Edge/Brave/Opera history files
+ ChromiumPresence - Checks if interesting Chrome/Edge/Brave/Opera files exist
+ CloudCredentials - AWS/Google/Azure/Bluemix cloud credential files
+ CloudSyncProviders - All configured Office 365 endpoints (tenants and teamsites) which are synchronised by OneDrive.
CredEnum - Enumerates the current user's saved credentials using CredEnumerate()
+ CredGuard - CredentialGuard configuration
dir - Lists files/folders. By default, lists users' downloads, documents, and desktop folders (arguments == [directory] [maxDepth] [regex] [boolIgnoreErrors]
+ DNSCache - DNS cache entries (via WMI)
+ DotNet - DotNet versions
+ DpapiMasterKeys - List DPAPI master keys
EnvironmentPath - Current environment %PATH$ folders and SDDL information
+ EnvironmentVariables - Current environment variables
+ ExplicitLogonEvents - Explicit Logon events (Event ID 4648) from the security event log. Default of 7 days, argument == last X days.
ExplorerMRUs - Explorer most recently used files (last 7 days, argument == last X days)
+ ExplorerRunCommands - Recent Explorer "run" commands
FileInfo - Information about a file (version information, timestamps, basic PE info, etc. argument(s) == file path(s)
+ FileZilla - FileZilla configuration files
+ FirefoxHistory - Parses any found FireFox history files
+ FirefoxPresence - Checks if interesting Firefox files exist
+ Hotfixes - Installed hotfixes (via WMI)
IdleTime - Returns the number of seconds since the current user's last input.
+ IEFavorites - Internet Explorer favorites
IETabs - Open Internet Explorer tabs
+ IEUrls - Internet Explorer typed URLs (last 7 days, argument == last X days)
+ InstalledProducts - Installed products via the registry
InterestingFiles - "Interesting" files matching various patterns in the user's folder. Note: takes non-trivial time.
+ InterestingProcesses - "Interesting" processes - defensive products and admin tools
InternetSettings - Internet settings including proxy configs and zones configuration
+ KeePass - Finds KeePass configuration files
+ LAPS - LAPS settings, if installed
+ LastShutdown - Returns the DateTime of the last system shutdown (via the registry).
LocalGPOs - Local Group Policy settings applied to the machine/local users
+ LocalGroups - Non-empty local groups, "-full" displays all groups (argument == computername to enumerate)
+ LocalUsers - Local users, whether they're active/disabled, and pwd last set (argument == computername to enumerate)
+ LogonEvents - Logon events (Event ID 4624) from the security event log. Default of 10 days, argument == last X days.
+ LogonSessions - Windows logon sessions
LOLBAS - Locates Living Off The Land Binaries and Scripts (LOLBAS) on the system. Note: takes non-trivial time.
+ LSASettings - LSA settings (including auth packages)
+ MappedDrives - Users' mapped drives (via WMI)
McAfeeConfigs - Finds McAfee configuration files
McAfeeSiteList - Decrypt any found McAfee SiteList.xml configuration files.
MicrosoftUpdates - All Microsoft updates (via COM)
MTPuTTY - MTPuTTY configuration files
NamedPipes - Named pipe names, any readable ACL information and associated process information.
+ NetworkProfiles - Windows network profiles
+ NetworkShares - Network shares exposed by the machine (via WMI)
+ NTLMSettings - NTLM authentication settings
OfficeMRUs - Office most recently used file list (last 7 days)
OneNote - List OneNote backup files
+ OptionalFeatures - List Optional Features/Roles (via WMI)
OracleSQLDeveloper - Finds Oracle SQLDeveloper connections.xml files
+ OSInfo - Basic OS info (i.e. architecture, OS version, etc.)
+ OutlookDownloads - List files downloaded by Outlook
+ PoweredOnEvents - Reboot and sleep schedule based on the System event log EIDs 1, 12, 13, 42, and 6008. Default of 7 days, argument == last X days.
+ PowerShell - PowerShell versions and security settings
+ PowerShellEvents - PowerShell script block logs (4104) with sensitive data.
+ PowerShellHistory - Searches PowerShell console history files for sensitive regex matches.
Printers - Installed Printers (via WMI)
+ ProcessCreationEvents - Process creation logs (4688) with sensitive data.
Processes - Running processes with file info company names that don't contain 'Microsoft', "-full" enumerates all processes
+ ProcessOwners - Running non-session 0 process list with owners. For remote use.
+ PSSessionSettings - Enumerates PS Session Settings from the registry
+ PuttyHostKeys - Saved Putty SSH host keys
+ PuttySessions - Saved Putty configuration (interesting fields) and SSH host keys
RDCManFiles - Windows Remote Desktop Connection Manager settings files
+ RDPSavedConnections - Saved RDP connections stored in the registry
+ RDPSessions - Current incoming RDP sessions (argument == computername to enumerate)
+ RDPsettings - Remote Desktop Server/Client Settings
RecycleBin - Items in the Recycle Bin deleted in the last 30 days - only works from a user context!
reg - Registry key values (HKLM\Software by default) argument == [Path] [intDepth] [Regex] [boolIgnoreErrors]
RPCMappedEndpoints - Current RPC endpoints mapped
+ SCCM - System Center Configuration Manager (SCCM) settings, if applicable
+ ScheduledTasks - Scheduled tasks (via WMI) that aren't authored by 'Microsoft', "-full" dumps all Scheduled tasks
SearchIndex - Query results from the Windows Search Index, default term of 'passsword'. (argument(s) == <search path> <pattern1,pattern2,...>
SecPackageCreds - Obtains credentials from security packages
+ SecureBoot - Secure Boot configuration
SecurityPackages - Enumerates the security packages currently available using EnumerateSecurityPackagesA()
Services - Services with file info company names that don't contain 'Microsoft', "-full" dumps all processes
+ SlackDownloads - Parses any found 'slack-downloads' files
+ SlackPresence - Checks if interesting Slack files exist
+ SlackWorkspaces - Parses any found 'slack-workspaces' files
+ SuperPutty - SuperPutty configuration files
+ Sysmon - Sysmon configuration from the registry
+ SysmonEvents - Sysmon process creation logs (1) with sensitive data.
TcpConnections - Current TCP connections and their associated processes and services
TokenGroups - The current token's local and domain groups
TokenPrivileges - Currently enabled token privileges (e.g. SeDebugPrivilege/etc.)
+ UAC - UAC system policies via the registry
UdpConnections - Current UDP connections and associated processes and services
UserRightAssignments - Configured User Right Assignments (e.g. SeDenyNetworkLogonRight, SeShutdownPrivilege, etc.) argument == computername to enumerate
WifiProfile - Enumerates the saved Wifi profiles and extract the ssid, authentication type, cleartext key/passphrase (when possible)
+ WindowsAutoLogon - Registry autologon information
WindowsCredentialFiles - Windows credential DPAPI blobs
+ WindowsDefender - Windows Defender settings (including exclusion locations)
+ WindowsEventForwarding - Windows Event Forwarding (WEF) settings via the registry
+ WindowsFirewall - Non-standard firewall rules, "-full" dumps all (arguments == allow/deny/tcp/udp/in/out/domain/private/public)
WindowsVault - Credentials saved in the Windows Vault (i.e. logins from Internet Explorer and Edge).
+ WMI - Runs a specified WMI query
WMIEventConsumer - Lists WMI Event Consumers
WMIEventFilter - Lists WMI Event Filters
WMIFilterBinding - Lists WMI Filter to Consumer Bindings
+ WSUS - Windows Server Update Services (WSUS) settings, if applicable
Seatbelt has the following command groups: All, User, System, Slack, Chromium, Remote, Misc
You can invoke command groups with "Seatbelt.exe <group>"
Or command groups except specific commands "Seatbelt.exe <group> -Command"
"Seatbelt.exe -group=all" runs all commands
"Seatbelt.exe -group=user" runs the following commands:
azuread, Certificates, CertificateThumbprints, ChromiumPresence, CloudCredentials,
CloudSyncProviders, CredEnum, dir, DpapiMasterKeys,
ExplorerMRUs, ExplorerRunCommands, FileZilla, FirefoxPresence,
IdleTime, IEFavorites, IETabs, IEUrls,
KeePass, MappedDrives, MTPuTTY, OfficeMRUs,
OneNote, OracleSQLDeveloper, PowerShellHistory, PuttyHostKeys,
PuttySessions, RDCManFiles, RDPSavedConnections, SecPackageCreds,
SlackDownloads, SlackPresence, SlackWorkspaces, SuperPutty,
TokenGroups, WindowsCredentialFiles, WindowsVault
"Seatbelt.exe -group=system" runs the following commands:
AMSIProviders, AntiVirus, AppLocker, ARPTable, AuditPolicies,
AuditPolicyRegistry, AutoRuns, Certificates, CertificateThumbprints,
CredGuard, DNSCache, DotNet, EnvironmentPath,
EnvironmentVariables, Hotfixes, InterestingProcesses, InternetSettings,
LAPS, LastShutdown, LocalGPOs, LocalGroups,
LocalUsers, LogonSessions, LSASettings, McAfeeConfigs,
NamedPipes, NetworkProfiles, NetworkShares, NTLMSettings,
OptionalFeatures, OSInfo, PoweredOnEvents, PowerShell,
Processes, PSSessionSettings, RDPSessions, RDPsettings,
SCCM, SecureBoot, Services, Sysmon,
TcpConnections, TokenPrivileges, UAC, UdpConnections,
UserRightAssignments, WifiProfile, WindowsAutoLogon, WindowsDefender,
WindowsEventForwarding, WindowsFirewall, WMI, WMIEventConsumer,
WMIEventFilter, WMIFilterBinding, WSUS
"Seatbelt.exe -group=slack" runs the following commands:
SlackDownloads, SlackPresence, SlackWorkspaces
"Seatbelt.exe -group=chromium" runs the following commands:
ChromiumBookmarks, ChromiumHistory, ChromiumPresence
"Seatbelt.exe -group=remote" runs the following commands:
AMSIProviders, AntiVirus, AuditPolicyRegistry, ChromiumPresence, CloudCredentials,
DNSCache, DotNet, DpapiMasterKeys, EnvironmentVariables,
ExplicitLogonEvents, ExplorerRunCommands, FileZilla, Hotfixes,
InterestingProcesses, KeePass, LastShutdown, LocalGroups,
LocalUsers, LogonEvents, LogonSessions, LSASettings,
MappedDrives, NetworkProfiles, NetworkShares, NTLMSettings,
OptionalFeatures, OSInfo, PoweredOnEvents, PowerShell,
ProcessOwners, PSSessionSettings, PuttyHostKeys, PuttySessions,
RDPSavedConnections, RDPSessions, RDPsettings, SecureBoot,
Sysmon, WindowsDefender, WindowsEventForwarding, WindowsFirewall
"Seatbelt.exe -group=misc" runs the following commands:
ChromiumBookmarks, ChromiumHistory, ExplicitLogonEvents, FileInfo, FirefoxHistory,
InstalledProducts, InterestingFiles, LogonEvents, LOLBAS,
McAfeeSiteList, MicrosoftUpdates, OutlookDownloads, PowerShellEvents,
Printers, ProcessCreationEvents, ProcessOwners, RecycleBin,
reg, RPCMappedEndpoints, ScheduledTasks, SearchIndex,
SecurityPackages, SysmonEvents
Examples: 'Seatbelt.exe [Command2] ...' will run one or more specified checks only 'Seatbelt.exe -full' will return complete results for a command without any filtering. 'Seatbelt.exe " [argument]"' will pass an argument to a command that supports it (note the quotes). 'Seatbelt.exe -group=all' will run ALL enumeration checks, can be combined with "-full". 'Seatbelt.exe -group=all -AuditPolicies' will run all enumeration checks EXCEPT AuditPolicies, can be combined with "-full". 'Seatbelt.exe -computername=COMPUTER.DOMAIN.COM [-username=DOMAIN\USER -password=PASSWORD]' will run an applicable check remotely 'Seatbelt.exe -group=remote -computername=COMPUTER.DOMAIN.COM [-username=DOMAIN\USER -password=PASSWORD]' will run remote specific checks 'Seatbelt.exe -group=system -outputfile="C:\Temp\out.txt"' will run system checks and output to a .txt file. 'Seatbelt.exe -group=user -q -outputfile="C:\Temp\out.json"' will run in quiet mode with user checks and output to a .json file.
**注:** ユーザーを対象とする検索は、昇格されていない場合は現在のユーザーに対して、昇格されている場合はすべてのユーザーに対して実行されます。
## コマンドグループ
**注:** 多くのコマンドはデフォルトで何らかのフィルタリングを行います。`-full` 引数を指定するとフィルタリングされた出力が抑制されます。また、コマンドグループ `all` は現在のすべてのチェックを実行します。
例えば、次のコマンドはすべてのチェックを実行し、すべての出力を返します:
`Seatbelt.exe -group=all -full`
### system
システムに関する興味深いデータを収集するチェックを実行します。
実行方法: `Seatbelt.exe -group=system`
| コマンド | 説明 |
| ----------- | ----------- |
| AMSIProviders | AMSI に登録されているプロバイダ |
| AntiVirus | 登録されているアンチウイルス (WMI 経由) |
| AppLocker | AppLocker 設定 (インストールされている場合) |
| ARPTable | 現在の ARP テーブルとアダプタ情報を一覧表示 (arp -a と同等) |
| AuditPolicies | クラシックおよび拡張監査ポリシー設定を列挙 |
| AuditPolicyRegistry | レジストリ経由の監査設定 |
| AutoRuns | 自動実行される実行可能ファイル/スクリプト/プログラム |
| Certificates | ユーザーおよびマシンの個人証明書ファイル |
| CertificateThumbprints | システム上のすべての証明書ストア証明書の拇印 |
| CredGuard | CredentialGuard 構成 |
| DNSCache | DNS キャッシュエントリ (WMI 経由) |
| DotNet | .NET バージョン |
| EnvironmentPath | 現在の環境 %PATH$ フォルダと SDDL 情報 |
| EnvironmentVariables | 現在のユーザー環境変数 |
| Hotfixes | インストールされている修正プログラム (WMI 経由) |
| InterestingProcesses | "興味深い" プロセス - 防御製品および管理ツール |
| InternetSettings | プロキシ設定を含むインターネット設定 |
| LAPS | LAPS 設定 (インストールされている場合) |
| LastShutdown | 最後のシステムシャットダウンの日時を返します (レジストリ経由) |
| LocalGPOs | マシン/ローカルユーザーに適用されているローカルグループポリシー設定 |
| LocalGroups | 空でないローカルグループ、"full" ですべてのグループを表示 (引数 == 列挙するコンピュータ名) |
| LocalUsers | ローカルユーザー、アクティブ/無効の状態、パスワード最終設定日 (引数 == 列挙するコンピュータ名) |
| LogonSessions | セキュリティイベントログからのログオンイベント (イベント ID 4624)。デフォルトは 10 日間、引数 == 過去 X 日間。 |
| LSASettings | LSA 設定 (認証パッケージを含む) |
| McAfeeConfigs | McAfee 構成ファイルを検出 |
| NamedPipes | 名前付きパイプ名と読み取り可能な ACL 情報 |
| NetworkProfiles | Windows ネットワークプロファイル |
| NetworkShares | マシンが公開しているネットワーク共有 (WMI 経由) |
| NTLMSettings | NTLM 認証設定 |
| OptionalFeatures | TODO |
| OSInfo | 基本的な OS 情報 (アーキテクチャ、OS バージョンなど) |
| PoweredOnEvents | システムイベントログの EID 1、12、13、42、6008 に基づく再起動およびスリープスケジュール。デフォルトは 7 日間、引数 == 過去 X 日間。 |
| PowerShell | PowerShell バージョンとセキュリティ設定 |
| Processes | 実行中のプロセス。ファイル情報の会社名に 'Microsoft' が含まれないもの、"full" ですべてのプロセスを列挙 |
| PSSessionSettings | レジストリから PS セッション設定を列挙 |
| RDPSessions | 現在の受信 RDP セッション (引数 == 列挙するコンピュータ名) |
| RDPsettings | リモートデスクトップサーバー/クライアント設定 |
| SCCM | System Center Configuration Manager (SCCM) 設定 (該当する場合) |
| Services | ファイル情報の会社名に 'Microsoft' が含まれないサービス、"full" ですべてのプロセスをダンプ |
| Sysmon | レジストリからの Sysmon 構成 |
| TcpConnections | 現在の TCP 接続とそれに関連するプロセスおよびサービス |
| TokenPrivileges | 現在有効なトークン特権 (例: SeDebugPrivilege など) |
| UAC | レジストリ経由の UAC システムポリシー |
| UdpConnections | 現在の UDP 接続と関連するプロセスおよびサービス |
| UserRightAssignments | 構成されたユーザー権利の割り当て (例: SeDenyNetworkLogonRight、SeShutdownPrivilege など)。引数 == 列挙するコンピュータ名 |
| WifiProfile | TODO |
| WindowsAutoLogon | レジストリの自動ログオン情報 |
| WindowsDefender | Windows Defender 設定 (除外場所を含む) |
| WindowsEventForwarding | レジストリ経由の Windows Event Forwarding (WEF) 設定 |
| WindowsFirewall | 標準以外のファイアウォールルール、"full" ですべてをダンプ (引数 == allow/deny/tcp/udp/in/out/domain/private/public) |
| WMIEventConsumer | WMI イベントコンシューマを一覧表示 |
| WMIEventFilter | WMI イベントフィルタを一覧表示 |
| WMIFilterBinding | WMI フィルタとコンシューマのバインディングを一覧表示 |
| WSUS | Windows Server Update Services (WSUS) 設定 (該当する場合) |
### user
現在ログオンしているユーザー (昇格されていない場合) またはすべてのユーザー (昇格されている場合) に関する興味深いデータを収集するチェックを実行します。
実行方法: `Seatbelt.exe -group=user`
| コマンド | 説明 |
| ----------- | ----------- |
| Certificates | ユーザーおよびマシンの個人証明書ファイル |
| CertificateThumbprints | システム上のすべての証明書ストア証明書の拇印 |
| ChromiumPresence | 興味深い Chrome/Edge/Brave/Opera ファイルが存在するかチェック |
| CloudCredentials | AWS/Google/Azure クラウド認証情報ファイル |
| CloudSyncProviders | TODO |
| CredEnum | CredEnumerate() を使用して現在のユーザーの保存された資格情報を列挙 |
| dir | ファイル/フォルダを一覧表示。デフォルトでは、ユーザーのダウンロード、ドキュメント、デスクトップフォルダを一覧表示 (引数 == \<ディレクトリ\> \<深さ\> \<正規表現\> |
| DpapiMasterKeys | DPAPI マスターキーを一覧表示 |
| Dsregcmd | TODO |
| ExplorerMRUs | エクスプローラの最近使用したファイル (過去 7 日間、引数 == 過去 X 日間) |
| ExplorerRunCommands | 最近のエクスプローラ "実行" コマンド |
| FileZilla | FileZilla 構成ファイル |
| FirefoxPresence | 興味深い Firefox ファイルが存在するかチェック |
| IdleTime | 現在のユーザーの最後の入力からの経過秒数を返します。 |
| IEFavorites | Internet Explorer のお気に入り |
| IETabs | 開いている Internet Explorer タブ |
| IEUrls| Internet Explorer で入力された URL (過去 7 日間、引数 == 過去 X 日間) |
| KeePass | TODO |
| MappedDrives | ユーザーのマップ済みドライブ (WMI 経由) |
| OfficeMRUs | Office の最近使用したファイルリスト (過去 7 日間) |
| OneNote | TODO |
| OracleSQLDeveloper | TODO |
| PowerShellHistory | すべてのローカルユーザーを反復処理し、PowerShell コンソール履歴を読み取ろうと試み、成功した場合は出力します |
| PuttyHostKeys | 保存された Putty SSH ホストキー |
| PuttySessions | 保存された Putty 構成 (興味深いフィールド) と SSH ホストキー |
| RDCManFiles | Windows リモートデスクトップ接続マネージャー設定ファイル |
| RDPSavedConnections | レジストリに保存された RDP 接続 |
| SecPackageCreds | セキュリティパッケージから資格情報を取得 |
| SlackDownloads | 見つかった 'slack-downloads' ファイルを解析 |
| SlackPresence | 興味深い Slack ファイルが存在するかチェック |
| SlackWorkspaces | 見つかった 'slack-workspaces' ファイルを解析 |
| SuperPutty | SuperPutty 構成ファイル |
| TokenGroups | 現在のトークンのローカルおよびドメイングループ |
| WindowsCredentialFiles | Windows 資格情報 DPAPI ブロブ |
| WindowsVault | Windows Vault に保存された資格情報 (Internet Explorer および Edge からのログインなど)。 |
### misc
すべてのその他チェックを実行します。
実行方法: `Seatbelt.exe -group=misc`
| コマンド | 説明 |
| ----------- | ----------- |
| ChromiumBookmarks | 見つかった Chrome/Edge/Brave/Opera ブックマークファイルを解析 |
| ChromiumHistory | 見つかった Chrome/Edge/Brave/Opera 履歴ファイルを解析 |
| ExplicitLogonEvents | セキュリティイベントログからの明示的なログオンイベント (イベント ID 4648)。デフォルトは 7 日間、引数 == 過去 X 日間。 |
| FileInfo | ファイルに関する情報 (バージョン情報、タイムスタンプ、基本的な PE 情報など)。引数 == ファイルパス |
| FirefoxHistory | 見つかった FireFox 履歴ファイルを解析 |
| InstalledProducts | レジストリ経由のインストール済み製品 |
| InterestingFiles | ユーザーフォルダ内の様々なパターンに一致する "興味深い" ファイル。注: 時間がかかる場合があります。 |
| LogonEvents | セキュリティイベントログからのログオンイベント (イベント ID 4624)。デフォルトは 10 日間、引数 == 過去 X 日間。 |
| LOLBAS | システム上の Living Off The Land Binaries and Scripts (LOLBAS) を特定します。注: 時間がかかる場合があります。 |
| McAfeeSiteList | 見つかった McAfee SiteList.xml 構成ファイルを復号化します。 |
| MicrosoftUpdates | すべての Microsoft 更新プログラム (COM 経由) |
| OutlookDownloads | Outlook によってダウンロードされたファイルを一覧表示 |
| PowerShellEvents | 機密データを含む PowerShell スクリプトブロックログ (4104)。 |
| Printers | インストール済みプリンタ (WMI 経由) |
| ProcessCreationEvents | 機密データを含むプロセス作成ログ (4688)。 |
| ProcessOwners | 実行中の非セッション 0 プロセスの一覧と所有者。リモート使用向け。 |
| RecycleBin | 過去 30 日以内に削除されたごみ箱内のアイテム - ユーザーコンテキストでのみ動作します! |
| reg | レジストリキー値 (デフォルトは HKLM\Software)。引数 == [パス] [深さ] [正規表現] [エラー無視のブール値] |
| RPCMappedEndpoints | 現在の RPC エンドポイントマッピング |
| ScheduledTasks | 'Microsoft' 以外によって作成されたスケジュールタスク (WMI 経由)、"full" ですべてのスケジュールタスクをダンプ |
| SearchIndex | Windows Search Index からのクエリ結果、デフォルトの検索語は 'passsword'。(引数 == \<検索パス\> \<パターン1,パターン2,...\> |
| SecurityPackages | EnumerateSecurityPackagesA() を使用して現在利用可能なセキュリティパッケージを列挙 |
| SysmonEvents | 機密データを含む Sysmon プロセス作成ログ (1)。 |
### 追加のコマンドグループ
実行方法: `Seatbelt.exe -group=GROUPNAME`
| エイリアス | 説明 |
| ----------- | ----------- |
| Slack | "Slack*" で始まるモジュールを実行 |
| Chromium | "Chromium*" で始まるモジュールを実行 |
| Remote | 次のモジュールを実行 (リモートシステム用): AMSIProviders、AntiVirus、AuditPolicyRegistry、ChromiumPresence、CloudCredentials、DNSCache、DotNet、DpapiMasterKeys、EnvironmentVariables、ExplicitLogonEvents、ExplorerRunCommands、FileZilla、Hotfixes、InterestingProcesses、KeePass、LastShutdown、LocalGroups、LocalUsers、LogonEvents、LogonSessions、LSASettings、MappedDrives、NetworkProfiles、NetworkShares、NTLMSettings、OptionalFeatures、OSInfo、PoweredOnEvents、PowerShell、ProcessOwners、PSSessionSettings、PuttyHostKeys、PuttySessions、RDPSavedConnections、RDPSessions、RDPsettings、Sysmon、WindowsDefender、WindowsEventForwarding、WindowsFirewall |
## コマンド引数
引数を受け付けるコマンドは、その説明に記載されています。コマンドに引数を渡すには、コマンドと引数を二重引用符で囲みます。
例えば、次のコマンドは過去 30 日間の 4624 ログオンイベントを返します:
`Seatbelt.exe "LogonEvents 30"`
次のコマンドはレジストリを 3 階層深くクエリし、正規表現 `.*defini.*` に一致するキー/値名/値のみを返し、発生するエラーを無視します。
`Seatbelt.exe "reg \"HKLM\SOFTWARE\Microsoft\Windows Defender\" 3 .*defini.* true"`
## 出力
Seatbelt は、`-outputfile="C:\Path\file.txt"` 引数を使用して出力をファイルにリダイレクトできます。ファイルパスが .json で終わる場合、出力は構造化された JSON になります。
例えば、次のコマンドはシステムチェックの結果を txt ファイルに出力します:
`Seatbelt.exe -group=system -outputfile="C:\Temp\system.txt"`
## リモート列挙
ヘルプメニューで + と表示されるコマンドは、別のシステムに対してリモートで実行できます。これは、WMI クラスのクエリと、レジストリ列挙のための WMI の StdRegProv を介して WMI 経由で実行されます。
リモートシステムを列挙するには、`-computername=COMPUTER.DOMAIN.COM` を指定します。別のユーザー名とパスワードは、`-username=DOMAIN\USER -password=PASSWORD` で指定できます。
例えば、次のコマンドはリモートシステムに対してリモート重視のチェックを実行します:
`Seatbelt.exe -group=remote -computername=192.168.230.209 -username=THESHIRE\sam -password="yum \"po-ta-toes\""`
## 独自のモジュールの作成
Seatbelt の構造は完全にモジュール化されており、追加のコマンドモジュールをファイル構造にドロップして動的に読み込むことができます。
参考用に、コメント付きのコマンドモジュールテンプレートが `.\Seatbelt\Commands\Template.cs` にあります。ビルド後、モジュールを適切なファイルの場所にドロップし、Visual Studio ソリューションエクスプローラーでプロジェクトに含め、コンパイルします。
## コンパイル手順
Seatbelt のバイナリをリリースする予定はないため、自分でコンパイルする必要があります。
Seatbelt は .NET 3.5 および 4.0 に対して C# 8.0 の機能を使用して構築されており、[Visual Studio Community Edition](https://visualstudio.microsoft.com/downloads/) と互換性があります。プロジェクトの .sln ファイルを開き、"release" を選択してビルドするだけです。対象の .NET フレームワークバージョンを変更するには、[プロジェクトの設定を変更](https://github.com/GhostPack/Seatbelt/issues/27) してプロジェクトを再構築してください。
## 謝辞
Seatbelt は、研究全体で見つかったさまざまな収集項目、C# コードスニペット、PoC の断片をその機能に組み込んでいます。これらのアイデア、スニペット、および作者は、ソースコード内の適切な場所で強調表示されており、以下が含まれます:* [@andrewchiles](https://twitter.com/andrewchiles) の [HostEnum.ps1](https://github.com/threatexpress/red-team-scripts/blob/master/HostEnum.ps1) スクリプトと [@tifkin\_](https://twitter.com/tifkin_) の [Get-HostProfile.ps1](https://github.com/leechristensen/Random/blob/master/PowerShellScripts/Get-HostProfile.ps1) は、収集する多くのアーティファクトの着想を得る元となりました。
* [NetLocalGroupGetMembers に関する Boboes のコード](https://stackoverflow.com/questions/33935825/pinvoke-netlocalgroupgetmembers-runs-into-fatalexecutionengineerror/33939889#33939889)
* [マップ済みドライブ文字をネットワークパスに変換する ambyte のコード](https://gist.github.com/ambyte/01664dc7ee576f69042c)
* [現在のトークングループ情報を取得する Igor Korkhov のコード](https://stackoverflow.com/questions/2146153/how-to-get-the-logon-sid-in-c-sharp/2146418#2146418)
* [ホストが仮想マシンかどうかを判別する RobSiklos のスニペット](https://stackoverflow.com/questions/498371/how-to-detect-if-my-application-is-running-in-a-virtual-machine/11145280#11145280)
* [ファイル/フォルダのACL権限比較に関する JGU のスニペット](https://stackoverflow.com/questions/1410127/c-sharp-test-if-user-has-write-access-to-a-folder/21996345#21996345)
* [再帰的なファイル列挙パターンに関する Rod Stephens のコード](http://csharphelper.com/blog/2015/06/find-files-that-match-multiple-patterns-in-c/)
* [現在のトークン特権を列挙する SwDevMan81 のスニペット](https://stackoverflow.com/questions/4349743/setting-size-of-token-privileges-luid-and-attributes-array-returned-by-gettokeni)
* [Kerberos チケットキャッシュに関する Jared Atkinson の PowerShell 作品](https://github.com/Invoke-IR/ACE/blob/master/ACE-Management/PS-ACE/Scripts/ACE_Get-KerberosTicketCache.ps1)
* [darkmatter08 の Kerberos C# スニペット](https://www.dreamincode.net/forums/topic/135033-increment-memory-pointer-issue/)
* 多数の [PInvoke.net](https://www.pinvoke.net/) サンプル <3
* [ローカルセキュリティ機関を使用してユーザーセッションを列挙する Jared Hill の素晴らしい CodeProject](https://www.codeproject.com/Articles/18179/Using-the-Local-Security-Authority-to-Enumerate-Us)
* [ARPキャッシュのクエリに関する Fred のコード](https://social.technet.microsoft.com/Forums/lync/en-US/e949b8d6-17ad-4afc-88cd-0019a3ac9df9/powershell-alternative-to-arp-a?forum=ITCG)
* [TCP接続テーブルのクエリに関する ShuggyCoUk のスニペット](https://stackoverflow.com/questions/577433/which-pid-listens-on-a-given-port-in-c-sharp/577660#577660)
* [リフレクションを使用してC#からCOMオブジェクトと対話する yizhang82 の例](https://gist.github.com/yizhang82/a1268d3ea7295a8a1496e01d60ada816)
* [@djhohnstein](https://twitter.com/djhohnstein) の [SharpWeb プロジェクト](https://github.com/djhohnstein/SharpWeb/blob/master/Edge/SharpEdge.cs)
* [@djhohnstein](https://twitter.com/djhohnstein) の [EventLogParser プロジェクト](https://github.com/djhohnstein/EventLogParser)
* [@cmaddalena](https://twitter.com/cmaddalena) の [SharpCloud プロジェクト](https://github.com/chrismaddalena/SharpCloud)、BSD 3-Clause
* [@_RastaMouse](https://twitter.com/_RastaMouse) の [Watson プロジェクト](https://github.com/rasta-mouse/Watson/)、GPL ライセンス
* [@_RastaMouse](https://twitter.com/_RastaMouse) の [AppLocker 列挙に関する作業](https://rastamouse.me/2018/09/enumerating-applocker-config/)
* [@peewpw](https://twitter.com/peewpw) の [Invoke-WCMDump プロジェクト](https://github.com/peewpw/Invoke-WCMDump/blob/master/Invoke-WCMDump.ps1)、GPL ライセンス
* TrustedSec の [HoneyBadger プロジェクト](https://github.com/trustedsec/HoneyBadger/tree/master/modules/post/windows/gather)、BSD 3-Clause
* CENTRAL Solutions の [Audit User Rights Assignment プロジェクト](https://www.centrel-solutions.com/support/tools.aspx?feature=auditrights)、ライセンスなし
* 収集アイデアは [@ukstufus](https://twitter.com/ukstufus) の [Reconerator](https://github.com/stufus/reconerator) に触発されました
* Office MRU の場所とタイムスタンプ解析情報は Dustin Hurlbut の論文「[Microsoft Office 2007, 2010 - Registry Artifacts](https://ad-pdf.s3.amazonaws.com/Microsoft_Office_2007-2010_Registry_ArtifactsFINAL.pdf)」から
* [Windows Commands リスト](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/windows-commands)、機密性の高い正規表現の構築に使用
* [マッピングされたRPCエンドポイントの列挙に関する Ryan Ries のコード](https://stackoverflow.com/questions/21805038/how-do-i-pinvoke-rpcmgmtepeltinqnext)
* [EnumerateSecurityPackages() に関する Chris Haas の投稿](https://stackoverflow.com/a/5941873)
* [darkoperator](https://github.com/ghostpack/seatbelt/blob/HEAD/carlos_perez) の [HoneyBadger プロジェクトに関する作業](https://github.com/trustedsec/HoneyBadger)
* [@airzero24](https://twitter.com/airzero24) の [WMI レジストリ列挙](https://github.com/airzero24/WMIReg)に関する作業
* [RegistryKey.OpenBaseKey の代替案](https://stackoverflow.com/questions/26217199/what-are-some-alternatives-to-registrykey-openbasekey-in-net-3-5)に関する Alexandru の回答
* [JavaScriptSerializer に関する Tomas Vera の投稿](http://www.tomasvera.com/programming/using-javascriptserializer-to-parse-json-objects/)
* [ファイル/フォルダの再帰的リストに関する Marc Gravell のメモ](https://stackoverflow.com/a/929418)
* [@mattifestation](https://twitter.com/mattifestation) の [Sysmon ルールパーサー](https://github.com/mattifestation/PSSysmonTools/blob/master/PSSysmonTools/Code/SysmonRuleParser.ps1#L589-L595)
* spolnik の [Simple.CredentialsManager プロジェクト](https://github.com/spolnik/Simple.CredentialsManager)からの若干のインスピレーション、Apache 2 ライセンス
* [Credential Guard 設定に関するこの投稿](https://www.tenforums.com/tutorials/68926-verify-if-device-guard-enabled-disabled-windows-10-a.html)
* [ネットワークプロファイル情報に関するこのスレッド](https://social.technet.microsoft.com/Forums/windows/en-US/b0e13a16-51a6-4aca-8d44-c85e097f882b/nametype-in-nla-information-for-a-network-profile)
* [DateCreated および DateLastConnected SSID 値のデコード](http://cfed-ttf.blogspot.com/2009/08/decoding-datecreated-and.html)に関する Mark McKinnon の投稿
* この Specops の[グループポリシーキャッシングに関する投稿](https://specopssoft.com/blog/things-work-group-policy-caching/)
* [ごみ箱のアイテムを列挙する](https://stackoverflow.com/questions/18071412/list-filenames-in-the-recyclebin-with-c-sharp-without-using-any-external-files)に関する sa_ddam213 の StackOverflow 投稿
* [マネージドアセンブリ検出のコード](https://stackoverflow.com/a/15608028)に関する Kirill Osenkov のコード
* SecBuffer/SecBufferDesc クラス用の [Mono プロジェクト](https://github.com/mono/linux-packaging-mono/blob/d356d2b7db91d62b80a61eeb6fbc70a402ac3cac/external/corefx/LICENSE.TXT)
* [Elad Shamir](https://twitter.com/elad_shamir) と彼の [Internal-Monologue](https://github.com/eladshamir/Internal-Monologue/) プロジェクト、[Vincent Le Toux](https://twitter.com/mysmartlogon) の [DetectPasswordViaNTLMInFlow](https://github.com/vletoux/DetectPasswordViaNTLMInFlow/) プロジェクト、および Lee Christensen の [GetNTLMChallenge](https://github.com/leechristensen/GetNTLMChallenge/) プロジェクト。これらすべてが SecPackageCreds コマンドのインスピレーションとなりました。
* FileZilla および SuperPutty コマンドのインスピレーションとして、@leftp と @eksperience の [Gopher プロジェクト](https://github.com/EncodeGroup/Gopher)
* 元の McAfee SiteList.xml 復号コードに関する @funoverip
引用については十分な注意を払ったつもりですが、もし抜け漏れがありましたらお知らせください!