VulnScanners Logo

Active Directory

Seatbelt

Local Windows security enumeration.

windowspost-exploitation
seatbelt — terminal
$ Seatbelt.exe -group=all

What it does

Seatbelt runs a battery of host "safety checks" that gather security-relevant configuration and artifacts from a Windows system. It's used for local situational awareness and privilege-escalation hunting.

Common use cases

  • Enumerate a compromised Windows host for privilege-escalation vectors and misconfigurations.
  • Gather installed software, scheduled tasks, and service information for lateral targeting.
  • Audit local security settings including LSA protection, AppLocker, and Defender status.

Key features

  • Runs 90+ security checks across system, user, and network categories.
  • Supports targeted groups — All, System, User, Slack, Chromium — for focused enumeration.
  • Outputs results to the console, text files, or CSV for review and reporting.
  • Lightweight standalone binary that runs without dependencies or installation.

Source

https://github.com/GhostPack/Seatbelt

More Active Directory tools

Need hosted scanning instead of local tooling?

Run a scan in the browser →