After getting initial foothold let’s strat recon
ps

as we see we found interesting processes like sysmon and elastic-agent
Now let’s now go and enumerate the system using seatbelt.

execute-assembly C:\Tools\Seatbelt\Seatbelt\bin\Release\Seatbelt.exe -group=system

now let’s see if there is anything interesting.


Now let’s test screenshots.
screenshot

as we see we got the username and the password
Username: Dev\bfarmer
Password: Sup3rman
Now let’s start keylogger.
keylogger

Now let’s see the clipboard.