Active Directory
Seatbelt
Local Windows security enumeration.
windowspost-exploitation
seatbelt — terminal
$ Seatbelt.exe -group=allWhat it does
Seatbelt runs a battery of host "safety checks" that gather security-relevant configuration and artifacts from a Windows system. It's used for local situational awareness and privilege-escalation hunting.
Common use cases
- •Enumerate a compromised Windows host for privilege-escalation vectors and misconfigurations.
- •Gather installed software, scheduled tasks, and service information for lateral targeting.
- •Audit local security settings including LSA protection, AppLocker, and Defender status.
Key features
- •Runs 90+ security checks across system, user, and network categories.
- •Supports targeted groups — All, System, User, Slack, Chromium — for focused enumeration.
- •Outputs results to the console, text files, or CSV for review and reporting.
- •Lightweight standalone binary that runs without dependencies or installation.
Source
https://github.com/GhostPack/Seatbelt ↗More Active Directory tools
Need hosted scanning instead of local tooling?
Run a scan in the browser →