Seatbelt is an open-source C# Windows host-enumeration and security-assessment tool used for post-exploitation reconnaissance. It conducts in-memory surveys of local system configuration and can enumerate credential-related artifacts, including PuTTY SSH host-key information. Seatbelt is used by red teams and has also appeared in intrusions and public post-exploitation-framework workflows, where it may be downloaded, compiled, executed, and removed after collection. It is distinct from Swiftbelt, a Swift-based macOS enumeration tool inspired by Seatbelt.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Sliver – We tested ... execute-assembly against Seatbelt and Rubeus ... Watching execute-assembly Rubeus.exe kerberoast complete successfully against a domain controller, through a WASM-bridged COM call into the CLR running a loaded Rubeus assembly, was significantly more rewarding ...
SharpChrome and SeatBelt ... were also used for credential-dumping. SharpChrome is a Chrome-specific implementation of SharpDPAPI and attempts to decrypt logins and cookies.
T1552.001 Credential in Files ... This EQL query uses the process.entity_id field to detect a process accessing multiple sensitive files in a short period of time.
T1555 - Credentials from password stores Extracts passwords from credential stores using tools such as SharpChrome, Seatbelt, and net-GPPPassword
T1555.003 Credentials from Web Browsers ... Here are detections of Chrome Login Data file access by different infostealers (Poulight Stealer, AgentTesla).
Starting with Windows 7, the credential manager allows users to store credentials for websites and network resources. Credential files are stored in C:\Users\<USER>\AppData\Local\Microsoft\Credentials\ ... These files are protected with user (or system) specific DPAPI masterkeys.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An offensive security and exploitation tool mentioned as being used during an intrusion that also employed an AMSI bypass via reflection.
Seatbelt is a post-exploitation reconnaissance tool that collects host information such as OS details, logon sessions, scheduled tasks, and installed hotfixes. When run as a BOF (Beacon Object File) within a C2 framework like Sliver, it operates entirely in memory, reducing disk artifacts and increasing stealth.
A named post-exploitation enumeration tool referenced only as the inspiration for Swiftbelt; no use of SeatBelt in the REF9134 intrusion is reported.
Windows security-assessment and enumeration tool that can identify credential-related files and registry data, including PuTTY SSH host keys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.