After getting initial foothold let’s strat recon
ps

as we see we found interesting processes like sysmon and elastic-agent
Now let’s now go and enumerate the system using seatbelt.

execute-assembly C:\\Tools\\Seatbelt\\Seatbelt\\bin\\Release\\Seatbelt.exe -group=system

now let’s see if there is anything interesting.


Now let’s test screenshots.
screenshot

as we see we got the username and the password
Username: Dev\\bfarmer
Password: Sup3rman
Now let’s start keylogger.
keylogger

Now let’s see the clipboard.