Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
Seatbelt — Seatbelt는 공격 및 방어 보안 관점에서 모두 중요한 보안 지향 호스트 조사 "안전 점검"을 수행하는 C# 프로젝트입니다. | Kitploit
도구/GitHubGitHub/ghostpack/seatbelt
Defensive ToolsPrivilege EscalationReconnaissanceVulnerability AnalysisInformation GatheringPost-ExploitationPenetration TestingRed Teaming
GitHubghostpack/seatbelt

Seatbelt

Seatbelt는 공격 및 방어 보안 관점에서 모두 중요한 보안 지향 호스트 조사 "안전 점검"을 수행하는 C# 프로젝트입니다.

저장소 보기
4.7k7641년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

Seatbelt


Seatbelt는 공격 및 방어 보안 관점 모두에서 관련된 여러 보안 지향 호스트 조사 "안전 점검"을 수행하는 C# 프로젝트입니다.

@andrewchiles' HostEnum.ps1 스크립트와 @tifkin_의 Get-HostProfile.ps1은 수집할 많은 아티팩트에 대한 영감을 제공했습니다.

@harmj0y와 @tifkin_가 이 구현의 주요 작성자입니다.

Seatbelt는 BSD 3-Clause 라이선스에 따라 라이선스가 부여됩니다.

목차

  • Seatbelt
    • 목차
    • 명령줄 사용법
    • 명령 그룹
      • system
      • user
      • misc
      • 추가 명령 그룹
    • 명령 인수
    • 출력
    • 원격 열거
    • 자체 모듈 구축
    • 컴파일 지침
    • 감사의 말

명령줄 사용법```

root@kitploit:~
                    %&&@@@&&                                                                                  
                    &&&&&&&%%%,                       #&&@@@@@@%%%%%%###############%                         
                    &%&   %&%%                        &////(((&%%%%%#%################//((((###%%%%%%%%%%%%%%%

%%%%%%%%%%%######%%%#%%####% &%%**# @////(((&%%%%%%######################((((((((((((((((((( #%#%%%%%%%#######%#%%####### %&%,,,,,,,,,,,,,,,, @////(((&%%%%%#%#####################((((((((((((((((((( #%#%%%%%%#####%%#%#%%####### %%%,,,,,, ,,. ,, @////(((&%%%%%%%######################(#(((#(#(((((((((( #####%%%#################### &%%...... ... .. @////(((&%%%%%%%###############%######((#(#(####(((((((( #######%##########%######### %%%...... ... .. @////(((&%%%%%#########################(#(#######((##### ###%##%%#################### &%%............... @////(((&%%%%%%%%##############%#######(#########((##### #####%###################### %%%.. @////(((&%%%%%%%################
&%& %%%%% Seatbelt %////(((&%%%%%%%%#############*
&%%&&&%%%%% v1.2.1 ,(((&%%%%%%%%%%%%%%%%%,
#%%%%##,

Available commands (+ means remote usage is supported):

root@kitploit:~
+ AMSIProviders          - Providers registered for AMSI
+ AntiVirus              - Registered antivirus (via WMI)
+ AppLocker              - AppLocker settings, if installed
  ARPTable               - Lists the current ARP table and adapter information (equivalent to arp -a)
  AuditPolicies          - Enumerates classic and advanced audit policy settings
+ AuditPolicyRegistry    - Audit settings via the registry
+ AutoRuns               - Auto run executables/scripts/programs
  azuread                - Return AzureAD info
  Certificates           - Finds user and machine personal certificate files
  CertificateThumbprints - Finds thumbprints for all certificate store certs on the system
+ ChromiumBookmarks      - Parses any found Chrome/Edge/Brave/Opera bookmark files
+ ChromiumHistory        - Parses any found Chrome/Edge/Brave/Opera history files
+ ChromiumPresence       - Checks if interesting Chrome/Edge/Brave/Opera files exist
+ CloudCredentials       - AWS/Google/Azure/Bluemix cloud credential files
+ CloudSyncProviders     - All configured Office 365 endpoints (tenants and teamsites) which are synchronised by OneDrive.
  CredEnum               - Enumerates the current user's saved credentials using CredEnumerate()
+ CredGuard              - CredentialGuard configuration
  dir                    - Lists files/folders. By default, lists users' downloads, documents, and desktop folders (arguments == [directory] [maxDepth] [regex] [boolIgnoreErrors]
+ DNSCache               - DNS cache entries (via WMI)
+ DotNet                 - DotNet versions
+ DpapiMasterKeys        - List DPAPI master keys
  EnvironmentPath        - Current environment %PATH$ folders and SDDL information
+ EnvironmentVariables   - Current environment variables
+ ExplicitLogonEvents    - Explicit Logon events (Event ID 4648) from the security event log. Default of 7 days, argument == last X days.
  ExplorerMRUs           - Explorer most recently used files (last 7 days, argument == last X days)
+ ExplorerRunCommands    - Recent Explorer "run" commands
  FileInfo               - Information about a file (version information, timestamps, basic PE info, etc. argument(s) == file path(s)
+ FileZilla              - FileZilla configuration files
+ FirefoxHistory         - Parses any found FireFox history files
+ FirefoxPresence        - Checks if interesting Firefox files exist
+ Hotfixes               - Installed hotfixes (via WMI)
  IdleTime               - Returns the number of seconds since the current user's last input.
+ IEFavorites            - Internet Explorer favorites
  IETabs                 - Open Internet Explorer tabs
+ IEUrls                 - Internet Explorer typed URLs (last 7 days, argument == last X days)
+ InstalledProducts      - Installed products via the registry
  InterestingFiles       - "Interesting" files matching various patterns in the user's folder. Note: takes non-trivial time.
+ InterestingProcesses   - "Interesting" processes - defensive products and admin tools
  InternetSettings       - Internet settings including proxy configs and zones configuration
+ KeePass                - Finds KeePass configuration files
+ LAPS                   - LAPS settings, if installed
+ LastShutdown           - Returns the DateTime of the last system shutdown (via the registry).
  LocalGPOs              - Local Group Policy settings applied to the machine/local users
+ LocalGroups            - Non-empty local groups, "-full" displays all groups (argument == computername to enumerate)
+ LocalUsers             - Local users, whether they're active/disabled, and pwd last set (argument == computername to enumerate)
+ LogonEvents            - Logon events (Event ID 4624) from the security event log. Default of 10 days, argument == last X days.
+ LogonSessions          - Windows logon sessions
  LOLBAS                 - Locates Living Off The Land Binaries and Scripts (LOLBAS) on the system. Note: takes non-trivial time.
+ LSASettings            - LSA settings (including auth packages)
+ MappedDrives           - Users' mapped drives (via WMI)
  McAfeeConfigs          - Finds McAfee configuration files
  McAfeeSiteList         - Decrypt any found McAfee SiteList.xml configuration files.
  MicrosoftUpdates       - All Microsoft updates (via COM)
  MTPuTTY                - MTPuTTY configuration files
  NamedPipes             - Named pipe names, any readable ACL information and associated process information.
+ NetworkProfiles        - Windows network profiles
+ NetworkShares          - Network shares exposed by the machine (via WMI)
+ NTLMSettings           - NTLM authentication settings
  OfficeMRUs             - Office most recently used file list (last 7 days)
  OneNote                - List OneNote backup files
+ OptionalFeatures       - List Optional Features/Roles (via WMI)
  OracleSQLDeveloper     - Finds Oracle SQLDeveloper connections.xml files
+ OSInfo                 - Basic OS info (i.e. architecture, OS version, etc.)
+ OutlookDownloads       - List files downloaded by Outlook
+ PoweredOnEvents        - Reboot and sleep schedule based on the System event log EIDs 1, 12, 13, 42, and 6008. Default of 7 days, argument == last X days.
+ PowerShell             - PowerShell versions and security settings
+ PowerShellEvents       - PowerShell script block logs (4104) with sensitive data.
+ PowerShellHistory      - Searches PowerShell console history files for sensitive regex matches.
  Printers               - Installed Printers (via WMI)
+ ProcessCreationEvents  - Process creation logs (4688) with sensitive data.
  Processes              - Running processes with file info company names that don't contain 'Microsoft', "-full" enumerates all processes
+ ProcessOwners          - Running non-session 0 process list with owners. For remote use.
+ PSSessionSettings      - Enumerates PS Session Settings from the registry
+ PuttyHostKeys          - Saved Putty SSH host keys
+ PuttySessions          - Saved Putty configuration (interesting fields) and SSH host keys
  RDCManFiles            - Windows Remote Desktop Connection Manager settings files
+ RDPSavedConnections    - Saved RDP connections stored in the registry
+ RDPSessions            - Current incoming RDP sessions (argument == computername to enumerate)
+ RDPsettings            - Remote Desktop Server/Client Settings
  RecycleBin             - Items in the Recycle Bin deleted in the last 30 days - only works from a user context!
  reg                    - Registry key values (HKLM\Software by default) argument == [Path] [intDepth] [Regex] [boolIgnoreErrors]
  RPCMappedEndpoints     - Current RPC endpoints mapped
+ SCCM                   - System Center Configuration Manager (SCCM) settings, if applicable
+ ScheduledTasks         - Scheduled tasks (via WMI) that aren't authored by 'Microsoft', "-full" dumps all Scheduled tasks
  SearchIndex            - Query results from the Windows Search Index, default term of 'passsword'. (argument(s) == <search path> <pattern1,pattern2,...>
  SecPackageCreds        - Obtains credentials from security packages
+ SecureBoot             - Secure Boot configuration
  SecurityPackages       - Enumerates the security packages currently available using EnumerateSecurityPackagesA()
  Services               - Services with file info company names that don't contain 'Microsoft', "-full" dumps all processes
+ SlackDownloads         - Parses any found 'slack-downloads' files
+ SlackPresence          - Checks if interesting Slack files exist
+ SlackWorkspaces        - Parses any found 'slack-workspaces' files
+ SuperPutty             - SuperPutty configuration files
+ Sysmon                 - Sysmon configuration from the registry
+ SysmonEvents           - Sysmon process creation logs (1) with sensitive data.
  TcpConnections         - Current TCP connections and their associated processes and services
  TokenGroups            - The current token's local and domain groups
  TokenPrivileges        - Currently enabled token privileges (e.g. SeDebugPrivilege/etc.)
+ UAC                    - UAC system policies via the registry
  UdpConnections         - Current UDP connections and associated processes and services
  UserRightAssignments   - Configured User Right Assignments (e.g. SeDenyNetworkLogonRight, SeShutdownPrivilege, etc.) argument == computername to enumerate
  WifiProfile            - Enumerates the saved Wifi profiles and extract the ssid, authentication type, cleartext key/passphrase (when possible)
+ WindowsAutoLogon       - Registry autologon information
  WindowsCredentialFiles - Windows credential DPAPI blobs
+ WindowsDefender        - Windows Defender settings (including exclusion locations)
+ WindowsEventForwarding - Windows Event Forwarding (WEF) settings via the registry
+ WindowsFirewall        - Non-standard firewall rules, "-full" dumps all (arguments == allow/deny/tcp/udp/in/out/domain/private/public)
  WindowsVault           - Credentials saved in the Windows Vault (i.e. logins from Internet Explorer and Edge).
+ WMI                    - Runs a specified WMI query
  WMIEventConsumer       - Lists WMI Event Consumers
  WMIEventFilter         - Lists WMI Event Filters
  WMIFilterBinding       - Lists WMI Filter to Consumer Bindings
+ WSUS                   - Windows Server Update Services (WSUS) settings, if applicable

Seatbelt has the following command groups: All, User, System, Slack, Chromium, Remote, Misc

root@kitploit:~
You can invoke command groups with         "Seatbelt.exe <group>"


Or command groups except specific commands "Seatbelt.exe <group> -Command"

"Seatbelt.exe -group=all" runs all commands

"Seatbelt.exe -group=user" runs the following commands:

root@kitploit:~
    azuread, Certificates, CertificateThumbprints, ChromiumPresence, CloudCredentials, 
    CloudSyncProviders, CredEnum, dir, DpapiMasterKeys, 
    ExplorerMRUs, ExplorerRunCommands, FileZilla, FirefoxPresence, 
    IdleTime, IEFavorites, IETabs, IEUrls, 
    KeePass, MappedDrives, MTPuTTY, OfficeMRUs, 
    OneNote, OracleSQLDeveloper, PowerShellHistory, PuttyHostKeys, 
    PuttySessions, RDCManFiles, RDPSavedConnections, SecPackageCreds, 
    SlackDownloads, SlackPresence, SlackWorkspaces, SuperPutty, 
    TokenGroups, WindowsCredentialFiles, WindowsVault

"Seatbelt.exe -group=system" runs the following commands:

root@kitploit:~
    AMSIProviders, AntiVirus, AppLocker, ARPTable, AuditPolicies, 
    AuditPolicyRegistry, AutoRuns, Certificates, CertificateThumbprints, 
    CredGuard, DNSCache, DotNet, EnvironmentPath, 
    EnvironmentVariables, Hotfixes, InterestingProcesses, InternetSettings, 
    LAPS, LastShutdown, LocalGPOs, LocalGroups, 
    LocalUsers, LogonSessions, LSASettings, McAfeeConfigs, 
    NamedPipes, NetworkProfiles, NetworkShares, NTLMSettings, 
    OptionalFeatures, OSInfo, PoweredOnEvents, PowerShell, 
    Processes, PSSessionSettings, RDPSessions, RDPsettings, 
    SCCM, SecureBoot, Services, Sysmon, 
    TcpConnections, TokenPrivileges, UAC, UdpConnections, 
    UserRightAssignments, WifiProfile, WindowsAutoLogon, WindowsDefender, 
    WindowsEventForwarding, WindowsFirewall, WMI, WMIEventConsumer, 
    WMIEventFilter, WMIFilterBinding, WSUS

"Seatbelt.exe -group=slack" runs the following commands:

root@kitploit:~
    SlackDownloads, SlackPresence, SlackWorkspaces

"Seatbelt.exe -group=chromium" runs the following commands:

root@kitploit:~
    ChromiumBookmarks, ChromiumHistory, ChromiumPresence

"Seatbelt.exe -group=remote" runs the following commands:

root@kitploit:~
    AMSIProviders, AntiVirus, AuditPolicyRegistry, ChromiumPresence, CloudCredentials, 
    DNSCache, DotNet, DpapiMasterKeys, EnvironmentVariables, 
    ExplicitLogonEvents, ExplorerRunCommands, FileZilla, Hotfixes, 
    InterestingProcesses, KeePass, LastShutdown, LocalGroups, 
    LocalUsers, LogonEvents, LogonSessions, LSASettings, 
    MappedDrives, NetworkProfiles, NetworkShares, NTLMSettings, 
    OptionalFeatures, OSInfo, PoweredOnEvents, PowerShell, 
    ProcessOwners, PSSessionSettings, PuttyHostKeys, PuttySessions, 
    RDPSavedConnections, RDPSessions, RDPsettings, SecureBoot, 
    Sysmon, WindowsDefender, WindowsEventForwarding, WindowsFirewall
    

"Seatbelt.exe -group=misc" runs the following commands:

root@kitploit:~
    ChromiumBookmarks, ChromiumHistory, ExplicitLogonEvents, FileInfo, FirefoxHistory, 
    InstalledProducts, InterestingFiles, LogonEvents, LOLBAS, 
    McAfeeSiteList, MicrosoftUpdates, OutlookDownloads, PowerShellEvents, 
    Printers, ProcessCreationEvents, ProcessOwners, RecycleBin, 
    reg, RPCMappedEndpoints, ScheduledTasks, SearchIndex, 
    SecurityPackages, SysmonEvents

Examples: 'Seatbelt.exe [Command2] ...' will run one or more specified checks only 'Seatbelt.exe -full' will return complete results for a command without any filtering. 'Seatbelt.exe " [argument]"' will pass an argument to a command that supports it (note the quotes). 'Seatbelt.exe -group=all' will run ALL enumeration checks, can be combined with "-full". 'Seatbelt.exe -group=all -AuditPolicies' will run all enumeration checks EXCEPT AuditPolicies, can be combined with "-full". 'Seatbelt.exe -computername=COMPUTER.DOMAIN.COM [-username=DOMAIN\USER -password=PASSWORD]' will run an applicable check remotely 'Seatbelt.exe -group=remote -computername=COMPUTER.DOMAIN.COM [-username=DOMAIN\USER -password=PASSWORD]' will run remote specific checks 'Seatbelt.exe -group=system -outputfile="C:\Temp\out.txt"' will run system checks and output to a .txt file. 'Seatbelt.exe -group=user -q -outputfile="C:\Temp\out.json"' will run in quiet mode with user checks and output to a .json file.

root@kitploit:~
**참고:** 대상 사용자가 일반 사용자일 경우 현재 사용자에 대해, 관리자 권한일 경우 모든 사용자에 대해 검색을 실행합니다.


## 명령 그룹

**참고:** 많은 명령이 기본적으로 일부 필터링을 수행합니다. `-full` 인수를 제공하면 필터링된 출력이 방지됩니다. 또한 `all` 명령 그룹은 현재 모든 검사를 실행합니다.

예를 들어, 다음 명령은 모든 검사를 실행하고 모든 출력을 반환합니다:

`Seatbelt.exe -group=all -full`

### system

시스템에 대한 흥미로운 데이터를 수집하는 검사를 실행합니다.

다음으로 실행: `Seatbelt.exe -group=system`

| 명령 | 설명 |
| ----------- | ----------- |
| AMSIProviders | AMSI에 등록된 공급자 |
| AntiVirus | 등록된 백신 (WMI를 통해) |
| AppLocker | AppLocker 설정 (설치된 경우) |
| ARPTable | 현재 ARP 테이블과 어댑터 정보를 나열합니다 (arp -a와 동일) |
| AuditPolicies | 클래식 및 고급 감사 정책 설정을 열거합니다 |
| AuditPolicyRegistry | 레지스트리를 통한 감사 설정 |
| AutoRuns | 자동 실행 실행 파일/스크립트/프로그램 |
| Certificates | 사용자 및 머신 개인 인증서 파일 |
| CertificateThumbprints | 시스템의 모든 인증서 저장소 인증서에 대한 지문 |
| CredGuard | CredentialGuard 구성 |
| DNSCache | DNS 캐시 항목 (WMI를 통해) |
| DotNet | DotNet 버전 |
| EnvironmentPath | 현재 환경 %PATH$ 폴더 및 SDDL 정보 |
| EnvironmentVariables | 현재 사용자 환경 변수 |
| Hotfixes | 설치된 핫픽스 (WMI를 통해) |
| InterestingProcesses | "흥미로운" 프로세스 – 방어 제품 및 관리 도구 |
| InternetSettings | 프록시 구성을 포함한 인터넷 설정 |
| LAPS | LAPS 설정 (설치된 경우) |
| LastShutdown | 마지막 시스템 종료의 날짜/시간을 반환합니다 (레지스트리를 통해) |
| LocalGPOs | 머신/로컬 사용자에 적용된 로컬 그룹 정책 설정 |
| LocalGroups | 비어 있지 않은 로컬 그룹, "full"은 모든 그룹을 표시합니다 (인수 == 열거할 컴퓨터 이름) |
| LocalUsers | 로컬 사용자, 활성/비활성 여부 및 암호 마지막 설정 시간 (인수 == 열거할 컴퓨터 이름) |
| LogonSessions | 보안 이벤트 로그의 로그온 이벤트 (이벤트 ID 4624). 기본값 10일, 인수 == 마지막 X일. |
| LSASettings | LSA 설정 (인증 패키지 포함) |
| McAfeeConfigs | McAfee 구성 파일을 찾습니다 |
| NamedPipes | 명명된 파이프 이름 및 읽을 수 있는 ACL 정보 |
| NetworkProfiles | Windows 네트워크 프로필 |
| NetworkShares | 머신이 노출하는 네트워크 공유 (WMI를 통해) |
| NTLMSettings | NTLM 인증 설정 |
| OptionalFeatures | TODO |
| OSInfo | 기본 OS 정보 (예: 아키텍처, OS 버전 등) |
| PoweredOnEvents | 시스템 이벤트 로그 EID 1, 12, 13, 42 및 6008을 기반으로 한 재부팅 및 절전 일정. 기본값 7일, 인수 == 마지막 X일. |
| PowerShell | PowerShell 버전 및 보안 설정 |
| Processes | 'Microsoft'를 포함하지 않는 파일 정보 회사 이름을 가진 실행 중인 프로세스, "full"은 모든 프로세스를 열거합니다 |
| PSSessionSettings | 레지스트리에서 PS 세션 설정을 열거합니다 |
| RDPSessions | 현재 들어오는 RDP 세션 (인수 == 열거할 컴퓨터 이름) |
| RDPsettings | 원격 데스크톱 서버/클라이언트 설정 |
| SCCM | System Center Configuration Manager (SCCM) 설정 (해당하는 경우) |
| Services | 'Microsoft'를 포함하지 않는 파일 정보 회사 이름을 가진 서비스, "full"은 모든 서비스를 덤프합니다 |
| Sysmon | 레지스트리의 Sysmon 구성 |
| TcpConnections | 현재 TCP 연결 및 관련 프로세스와 서비스 |
| TokenPrivileges | 현재 활성화된 토큰 권한 (예: SeDebugPrivilege 등) |
| UAC | 레지스트리를 통한 UAC 시스템 정책 |
| UdpConnections | 현재 UDP 연결 및 관련 프로세스와 서비스 |
| UserRightAssignments | 구성된 사용자 권한 할당 (예: SeDenyNetworkLogonRight, SeShutdownPrivilege 등) 인수 == 열거할 컴퓨터 이름 |
| WifiProfile | TODO |
| WindowsAutoLogon | 레지스트리 자동 로그온 정보 |
| WindowsDefender | Windows Defender 설정 (제외 위치 포함) |
| WindowsEventForwarding | 레지스트리를 통한 Windows 이벤트 전달 (WEF) 설정 |
| WindowsFirewall | 비표준 방화벽 규칙, "full"은 모두 덤프합니다 (인수 == allow/deny/tcp/udp/in/out/domain/private/public) |
| WMIEventConsumer | WMI 이벤트 소비자를 나열합니다 |
| WMIEventFilter | WMI 이벤트 필터를 나열합니다 |
| WMIFilterBinding | WMI 필터-소비자 바인딩을 나열합니다 |
| WSUS | Windows Server Update Services (WSUS) 설정 (해당하는 경우) |


### user

현재 로그온한 사용자 (관리자 권한이 아닌 경우) 또는 모든 사용자 (관리자 권한인 경우)에 대한 흥미로운 데이터를 수집하는 검사를 실행합니다.

다음으로 실행: `Seatbelt.exe -group=user`

| 명령 | 설명 |
| ----------- | ----------- |
| Certificates | 사용자 및 머신 개인 인증서 파일 |
| CertificateThumbprints | 시스템의 모든 인증서 저장소 인증서에 대한 지문 |
| ChromiumPresence | 흥미로운 Chrome/Edge/Brave/Opera 파일이 존재하는지 확인합니다 |
| CloudCredentials | AWS/Google/Azure 클라우드 자격 증명 파일 |
| CloudSyncProviders | TODO |
| CredEnum | CredEnumerate()를 사용하여 현재 사용자의 저장된 자격 증명을 열거합니다 |
| dir | 파일/폴더를 나열합니다. 기본적으로 사용자의 다운로드, 문서 및 바탕 화면 폴더를 나열합니다 (인수 == \<디렉터리\> \<깊이\> \<정규식\>) |
| DpapiMasterKeys | DPAPI 마스터 키를 나열합니다 |
| Dsregcmd | TODO |
| ExplorerMRUs | 탐색기에서 가장 최근에 사용한 파일 (최근 7일, 인수 == 마지막 X일) |
| ExplorerRunCommands | 최근 탐색기 "실행" 명령 |
| FileZilla | FileZilla 구성 파일 |
| FirefoxPresence | 흥미로운 Firefox 파일이 존재하는지 확인합니다 |
| IdleTime | 현재 사용자의 마지막 입력 이후 경과된 초를 반환합니다 |
| IEFavorites | Internet Explorer 즐겨찾기 |
| IETabs | 열린 Internet Explorer 탭 |
| IEUrls| Internet Explorer에서 입력한 URL (최근 7일, 인수 == 마지막 X일) |
| KeePass | TODO |
| MappedDrives | 사용자의 매핑된 드라이브 (WMI를 통해) |
| OfficeMRUs | Office에서 가장 최근에 사용한 파일 목록 (최근 7일) |
| OneNote | TODO |
| OracleSQLDeveloper | TODO |
| PowerShellHistory | 모든 로컬 사용자를 반복하며 PowerShell 콘솔 기록을 읽으려고 시도하고, 성공하면 출력합니다 |
| PuttyHostKeys | 저장된 Putty SSH 호스트 키 |
| PuttySessions | 저장된 Putty 구성 (흥미로운 필드) 및 SSH 호스트 키 |
| RDCManFiles | Windows 원격 데스크톱 연결 관리자 설정 파일 |
| RDPSavedConnections | 레지스트리에 저장된 RDP 연결 |
| SecPackageCreds | 보안 패키지에서 자격 증명을 가져옵니다 |
| SlackDownloads | 발견된 'slack-downloads' 파일을 파싱합니다 |
| SlackPresence | 흥미로운 Slack 파일이 존재하는지 확인합니다 |
| SlackWorkspaces | 발견된 'slack-workspaces' 파일을 파싱합니다 |
| SuperPutty | SuperPutty 구성 파일 |
| TokenGroups | 현재 토큰의 로컬 및 도메인 그룹 |
| WindowsCredentialFiles | Windows 자격 증명 DPAPI blob |
| WindowsVault | Windows 자격 증명 보관소에 저장된 자격 증명 (예: Internet Explorer 및 Edge의 로그인 정보) |


### misc

모든 기타 검사를 실행합니다.

다음으로 실행: `Seatbelt.exe -group=misc`

| 명령 | 설명 |
| ----------- | ----------- |
| ChromiumBookmarks | 발견된 Chrome/Edge/Brave/Opera 북마크 파일을 파싱합니다 |
| ChromiumHistory | 발견된 Chrome/Edge/Brave/Opera 기록 파일을 파싱합니다 |
| ExplicitLogonEvents | 보안 이벤트 로그의 명시적 로그온 이벤트 (이벤트 ID 4648). 기본값 7일, 인수 == 마지막 X일. |
| FileInfo | 파일에 대한 정보 (버전 정보, 타임스탬프, 기본 PE 정보 등, 인수 == 파일 경로) |
| FirefoxHistory | 발견된 FireFox 기록 파일을 파싱합니다 |
| InstalledProducts | 레지스트리를 통해 설치된 제품 |
| InterestingFiles | 사용자 폴더에서 다양한 패턴과 일치하는 "흥미로운" 파일. 참고: 시간이 많이 걸립니다. |
| LogonEvents | 보안 이벤트 로그의 로그온 이벤트 (이벤트 ID 4624). 기본값 10일, 인수 == 마지막 X일. |
| LOLBAS | 시스템에서 Living Off The Land 바이너리 및 스크립트 (LOLBAS)를 찾습니다. 참고: 시간이 많이 걸립니다. |
| McAfeeSiteList | 발견된 McAfee SiteList.xml 구성 파일을 해독합니다. |
| MicrosoftUpdates | 모든 Microsoft 업데이트 (COM을 통해) |
| OutlookDownloads | Outlook이 다운로드한 파일 목록 |
| PowerShellEvents | 민감한 데이터가 포함된 PowerShell 스크립트 블록 로그 (4104). |
| Printers | 설치된 프린터 (WMI를 통해) |
| ProcessCreationEvents | 민감한 데이터가 포함된 프로세스 생성 로그 (4688). |
| ProcessOwners | 소유자가 포함된 실행 중인 비세션 0 프로세스 목록. 원격 사용용. |
| RecycleBin | 지난 30일 동안 휴지통에 삭제된 항목 – 사용자 컨텍스트에서만 작동합니다! |
| reg | 레지스트리 키 값 (기본적으로 HKLM\Software) 인수 == [경로] [깊이] [정규식] [bool무시오류] |
| RPCMappedEndpoints | 현재 RPC 엔드포인트 매핑 |
| ScheduledTasks | 'Microsoft'가 작성하지 않은 예약된 작업 (WMI를 통해), "full"은 모든 예약된 작업을 덤프합니다 |
| SearchIndex | Windows 검색 인덱스의 쿼리 결과, 기본 검색어는 'password'. (인수 == \<검색 경로\> \<패턴1,패턴2,...\>) |
| SecurityPackages | EnumerateSecurityPackagesA()를 사용하여 현재 사용 가능한 보안 패키지를 열거합니다 |
| SysmonEvents | 민감한 데이터가 포함된 Sysmon 프로세스 생성 로그 (1). |


### 추가 명령 그룹

다음으로 실행: `Seatbelt.exe -group=GROUPNAME`

| 별칭 | 설명 |
| ----------- | ----------- |
| Slack | "Slack*"으로 시작하는 모듈을 실행합니다 |
| Chromium | "Chromium*"으로 시작하는 모듈을 실행합니다 |
| Remote | 다음 모듈을 실행합니다 (원격 시스템 사용용): AMSIProviders, AntiVirus, AuditPolicyRegistry, ChromiumPresence, CloudCredentials, DNSCache, DotNet, DpapiMasterKeys, EnvironmentVariables, ExplicitLogonEvents, ExplorerRunCommands, FileZilla, Hotfixes, InterestingProcesses, KeePass, LastShutdown, LocalGroups, LocalUsers, LogonEvents, LogonSessions, LSASettings, MappedDrives, NetworkProfiles, NetworkShares, NTLMSettings, OptionalFeatures, OSInfo, PoweredOnEvents, PowerShell, ProcessOwners, PSSessionSettings, PuttyHostKeys, PuttySessions, RDPSavedConnections, RDPSessions, RDPsettings, Sysmon, WindowsDefender, WindowsEventForwarding, WindowsFirewall |


## 명령 인수

인수를 받는 명령은 설명에 표시되어 있습니다. 명령에 인수를 전달하려면 명령과 인수를 큰따옴표로 묶습니다.

예를 들어, 다음 명령은 지난 30일 동안의 4624 로그온 이벤트를 반환합니다:

`Seatbelt.exe "LogonEvents 30"`

다음 명령은 레지스트리를 세 단계 깊이로 쿼리하여 정규식 `.*defini.*`와 일치하는 키/값 이름/값만 반환하고, 발생하는 모든 오류를 무시합니다.

`Seatbelt.exe "reg \"HKLM\SOFTWARE\Microsoft\Windows Defender\" 3 .*defini.* true"`


## 출력

Seatbelt는 `-outputfile="C:\Path\file.txt"` 인수를 사용하여 출력을 파일로 리디렉션할 수 있습니다. 파일 경로가 .json으로 끝나면 출력은 구조화된 json이 됩니다.

예를 들어, 다음 명령은 시스템 검사 결과를 txt 파일로 출력합니다:

`Seatbelt.exe -group=system -outputfile="C:\Temp\system.txt"`


## 원격 열거

도움말 메뉴에 +로 표시된 명령은 다른 시스템에 대해 원격으로 실행할 수 있습니다. 이는 WMI 쿼리(WMI 클래스용)와 WMI의 StdRegProv(레지스트리 열거용)를 통해 수행됩니다.

원격 시스템을 열거하려면 `-computername=COMPUTER.DOMAIN.COM`을 제공하고, 대체 사용자 이름과 암호는 `-username=DOMAIN\USER -password=PASSWORD`로 지정할 수 있습니다.

예를 들어, 다음 명령은 원격 시스템에 대해 원격 중심 검사를 실행합니다:

`Seatbelt.exe -group=remote -computername=192.168.230.209 -username=THESHIRE\sam -password="yum \"po-ta-toes\""`


## 자체 모듈 구축

Seatbelt의 구조는 완전히 모듈식이므로 추가 명령 모듈을 파일 구조에 추가하고 동적으로 로드할 수 있습니다.

주석이 포함된 명령 모듈 템플릿이 참조용으로 `.\Seatbelt\Commands\Template.cs`에 있습니다. 빌드 후 모듈을 논리적 파일 위치에 넣고 Visual Studio 솔루션 탐색기에서 프로젝트에 포함시킨 다음 컴파일합니다.


## 컴파일 지침

Seatbelt에 대한 바이너리를 릴리스할 계획이 없으므로 직접 컴파일해야 합니다.

Seatbelt는 C# 8.0 기능을 사용하여 .NET 3.5 및 4.0에 대해 빌드되었으며 [Visual Studio Community Edition](https://visualstudio.microsoft.com/downloads/)과 호환됩니다. 프로젝트 .sln 파일을 열고 "release"를 선택한 후 빌드하기만 하면 됩니다. 대상 .NET 프레임워크 버전을 변경하려면 [프로젝트 설정을 수정](https://github.com/GhostPack/Seatbelt/issues/27)하고 프로젝트를 다시 빌드하십시오.


## 감사의 말

Seatbelt는 연구 과정에서 발견된 다양한 수집 항목, C# 코드 조각 및 PoC 일부를 기능에 통합했습니다. 이러한 아이디어, 코드 조각 및 작성자는 소스 코드의 적절한 위치에 강조 표시되어 있으며, 다음을 포함합니다:* [@andrewchiles](https://twitter.com/andrewchiles)의 [HostEnum.ps1](https://github.com/threatexpress/red-team-scripts/blob/master/HostEnum.ps1) 스크립트와 [@tifkin\_](https://twitter.com/tifkin_)의 [Get-HostProfile.ps1](https://github.com/leechristensen/Random/blob/master/PowerShellScripts/Get-HostProfile.ps1)은 수집할 아티팩트에 대한 많은 영감을 제공했습니다.
* 수집할 아티팩트에 대한 많은 영감은 [@andrewchiles](https://twitter.com/andrewchiles)의 [HostEnum.ps1](https://github.com/threatexpress/red-team-scripts/blob/master/HostEnum.ps1) 스크립트와 [@tifkin\_](https://twitter.com/tifkin_)의 [Get-HostProfile.ps1](https://github.com/leechristensen/Random/blob/master/PowerShellScripts/Get-HostProfile.ps1)에서 비롯되었습니다.
* [Boboes의 NetLocalGroupGetMembers 관련 코드](https://stackoverflow.com/questions/33935825/pinvoke-netlocalgroupgetmembers-runs-into-fatalexecutionengineerror/33939889#33939889)
* [ambyte의 매핑된 드라이브 문자를 네트워크 경로로 변환하는 코드](https://gist.github.com/ambyte/01664dc7ee576f69042c)
* [Igor Korkhov의 현재 토큰 그룹 정보 검색 코드](https://stackoverflow.com/questions/2146153/how-to-get-the-logon-sid-in-c-sharp/2146418#2146418)
* [RobSiklos의 호스트가 가상 머신인지 확인하는 코드 조각](https://stackoverflow.com/questions/498371/how-to-detect-if-my-application-is-running-in-a-virtual-machine/11145280#11145280)
* [JGU의 파일/폴더 ACL 권한 비교 코드 조각](https://stackoverflow.com/questions/1410127/c-sharp-test-if-user-has-write-access-to-a-folder/21996345#21996345)
* [Rod Stephens의 재귀적 파일 열거 패턴](http://csharphelper.com/blog/2015/06/find-files-that-match-multiple-patterns-in-c/)
* [SwDevMan81의 현재 토큰 권한 열거 코드 조각](https://stackoverflow.com/questions/4349743/setting-size-of-token-privileges-luid-and-attributes-array-returned-by-gettokeni)
* [Jared Atkinson의 Kerberos 티켓 캐시에 관한 PowerShell 작업](https://github.com/Invoke-IR/ACE/blob/master/ACE-Management/PS-ACE/Scripts/ACE_Get-KerberosTicketCache.ps1)
* [darkmatter08의 Kerberos C# 코드 조각](https://www.dreamincode.net/forums/topic/135033-increment-memory-pointer-issue/)
* 수많은 [PInvoke.net](https://www.pinvoke.net/) 샘플 <3
* [Jared Hill의 Local Security Authority를 사용하여 사용자 세션을 열거하는 CodeProject](https://www.codeproject.com/Articles/18179/Using-the-Local-Security-Authority-to-Enumerate-Us)
* [Fred의 ARP 캐시 쿼리 코드](https://social.technet.microsoft.com/Forums/lync/en-US/e949b8d6-17ad-4afc-88cd-0019a3ac9df9/powershell-alternative-to-arp-a?forum=ITCG)
* [ShuggyCoUk의 TCP 연결 테이블 쿼리 코드 조각](https://stackoverflow.com/questions/577433/which-pid-listens-on-a-given-port-in-c-sharp/577660#577660)
* [yizhang82의 리플렉션을 사용하여 C#에서 COM 객체와 상호 작용하는 예제](https://gist.github.com/yizhang82/a1268d3ea7295a8a1496e01d60ada816)
* [@djhohnstein](https://twitter.com/djhohnstein)의 [SharpWeb 프로젝트](https://github.com/djhohnstein/SharpWeb/blob/master/Edge/SharpEdge.cs)
* [@djhohnstein](https://twitter.com/djhohnstein)의 [EventLogParser 프로젝트](https://github.com/djhohnstein/EventLogParser)
* [@cmaddalena](https://twitter.com/cmaddalena)의 [SharpCloud 프로젝트](https://github.com/chrismaddalena/SharpCloud), BSD 3-Clause
* [@_RastaMouse](https://twitter.com/_RastaMouse)의 [Watson 프로젝트](https://github.com/rasta-mouse/Watson/), GPL License
* [@_RastaMouse](https://twitter.com/_RastaMouse)의 [AppLocker 열거 작업](https://rastamouse.me/2018/09/enumerating-applocker-config/)
* [@peewpw](https://twitter.com/peewpw)의 [Invoke-WCMDump 프로젝트](https://github.com/peewpw/Invoke-WCMDump/blob/master/Invoke-WCMDump.ps1), GPL License
* TrustedSec의 [HoneyBadger 프로젝트](https://github.com/trustedsec/HoneyBadger/tree/master/modules/post/windows/gather), BSD 3-Clause
* CENTRAL Solutions의 [사용자 권한 할당 감사 프로젝트](https://www.centrel-solutions.com/support/tools.aspx?feature=auditrights), 라이선스 없음
* [@ukstufus](https://twitter.com/ukstufus)의 [Reconerator](https://github.com/stufus/reconerator)에서 영감을 받은 수집 아이디어
* Office MRU 위치 및 타임스탬프 구문 분석 정보는 Dustin Hurlbut의 논문 [Microsoft Office 2007, 2010 - 레지스트리 아티팩트](https://ad-pdf.s3.amazonaws.com/Microsoft_Office_2007-2010_Registry_ArtifactsFINAL.pdf)에서 가져옴
* 민감한 정규식 구성을 위해 사용된 [Windows 명령어 목록](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/windows-commands)
* [Ryan Ries의 매핑된 RPC 엔드포인트 열거 코드](https://stackoverflow.com/questions/21805038/how-do-i-pinvoke-rpcmgmtepeltinqnext)
* [Chris Haas의 EnumerateSecurityPackages() 게시물](https://stackoverflow.com/a/5941873)
* [darkoperator](https://github.com/ghostpack/seatbelt/blob/HEAD/carlos_perez)의 [HoneyBadger 프로젝트](https://github.com/trustedsec/HoneyBadger) 작업
* [@airzero24](https://twitter.com/airzero24)의 [WMI 레지스트리 열거](https://github.com/airzero24/WMIReg) 작업
* Alexandru의 [RegistryKey.OpenBaseKey 대안](https://stackoverflow.com/questions/26217199/what-are-some-alternatives-to-registrykey-openbasekey-in-net-3-5)에 대한 답변
* Tomas Vera의 [JavaScriptSerializer 게시물](http://www.tomasvera.com/programming/using-javascriptserializer-to-parse-json-objects/)
* Marc Gravell의 [재귀적 파일/폴더 나열에 대한 메모](https://stackoverflow.com/a/929418)
* [@mattifestation](https://twitter.com/mattifestation)의 [Sysmon 규칙 파서](https://github.com/mattifestation/PSSysmonTools/blob/master/PSSysmonTools/Code/SysmonRuleParser.ps1#L589-L595)
* spolnik의 [Simple.CredentialsManager 프로젝트](https://github.com/spolnik/Simple.CredentialsManager)에서 영감을 받음, Apache 2 라이선스
* [Credential Guard 설정에 대한 이 게시물](https://www.tenforums.com/tutorials/68926-verify-if-device-guard-enabled-disabled-windows-10-a.html)
* 네트워크 프로필 정보에 관한 [이 스레드](https://social.technet.microsoft.com/Forums/windows/en-US/b0e13a16-51a6-4aca-8d44-c85e097f882b/nametype-in-nla-information-for-a-network-profile)
* Mark McKinnon의 [DateCreated 및 DateLastConnected SSID 값 디코딩 게시물](http://cfed-ttf.blogspot.com/2009/08/decoding-datecreated-and.html)
* 그룹 정책 캐싱에 관한 이 Specops [게시물](https://specopssoft.com/blog/things-work-group-policy-caching/)
* sa_ddam213의 StackOverflow 게시물 [외부 파일 없이 C#으로 휴지통 항목 나열](https://stackoverflow.com/questions/18071412/list-filenames-in-the-recyclebin-with-c-sharp-without-using-any-external-files)
* Kirill Osenkov의 [관리형 어셈블리 탐지 코드](https://stackoverflow.com/a/15608028)
* SecBuffer/SecBufferDesc 클래스를 위한 [Mono 프로젝트](https://github.com/mono/linux-packaging-mono/blob/d356d2b7db91d62b80a61eeb6fbc70a402ac3cac/external/corefx/LICENSE.TXT)
* [Elad Shamir](https://twitter.com/elad_shamir)와 그의 [Internal-Monologue](https://github.com/eladshamir/Internal-Monologue/) 프로젝트, [Vincent Le Toux](https://twitter.com/mysmartlogon)의 [DetectPasswordViaNTLMInFlow](https://github.com/vletoux/DetectPasswordViaNTLMInFlow/) 프로젝트, 그리고 Lee Christensen의 [GetNTLMChallenge](https://github.com/leechristensen/GetNTLMChallenge/) 프로젝트. 이 모든 것은 SecPackageCreds 명령에 영감을 주었습니다.
* @leftp와 @eksperience의 [Gopher 프로젝트](https://github.com/EncodeGroup/Gopher)는 FileZilla 및 SuperPutty 명령에 영감을 주었습니다.
* @funoverip의 원본 McAfee SiteList.xml 복호화 코드

인용을 위해 최선을 다했지만, 누군가/무언가를 빠뜨렸다면 알려주시기 바랍니다.
도구 다운로드