Security Account Manager (SAM) File Access
Description
Identifies access to the Security Account Manager (SAM) database file, which adversaries can use to recover password hashes for local accounts.
Query · eql
file where event.action == "open" and
file.path :
("?:\\WINDOWS\\SYSTEM32\\CONFIG\\SAM",
"\\??\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy*\\WINDOWS\\SYSTEM32\\CONFIG\\SAM",
"\\Device\\HarddiskVolume*\\WINDOWS\\SYSTEM32\\CONFIG\\SAM") and
user.id != null and process.executable : "?:\\*" and not process.pid == 4 and
not process.executable :
("?:\\Windows\\System32\\svchost.exe",
"?:\\Program Files (x86)\\*",
"?:\\Program Files\\*",
"?:\\Windows\\System32\\wuauclt.exe",
"?:\\$WINDOWS.~BT\\Sources\\SetupHost.exe",
"?:\\Windows\\System32\\vmwp.exe",
"?:\\Windows\\System32\\Dism.exe",
"?:\\Windows\\System32\\wbengine.exe",
"?:\\Windows\\System32\\mmc.exe",
"?:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*.exe",
"?:\\Windows\\System32\\sppsvc.exe",
"?:\\Windows\\System32\\backgroundTaskHost.exe",
"?:\\Windows\\System32\\lsass.exe",
"?:\\Windows\\System32\\SearchProtocolHost.exe",
"?:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*.exe",
"?:\\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection\\Platform\\*.exe",
"?:\\Program Files\\Windows Defender Advanced Threat Protection\\*.exe",
"?:\\Program Files\\Microsoft Monitoring Agent\\Agent\\*.exe",
"?:\\Windows\\System32\\SrTasks.exe",
"?:\\Windows\\System32\\rstrui.exe",
"?:\\Windows\\System32\\RecoveryDrive.exe",
"?:\\Windows\\System32\\MRT.exe",
"?:\\rsyncd\\bin\\rsync.exe",
"?:\\PCBP\\wbps.exe",
"?:\\Windows\\System32\\Robocopy.exe",
"D:\\PROGRAMS\\Commvault\\ContentStore\\Base\\CLBackup.exe") and
/* mounted OS install */
not file.path : "?:\\?*\\Windows\\System32\\*" and
not (process.code_signature.subject_name :
("ESET, spol. s r.o.", "Commvault Systems, Inc.", "Eric R. Zimmerman", "EFOLDER, INC.", "Absolute Software Corp.",
"EFOLDER, INC.", "International Business Machines Corporation") and
process.code_signature.trusted == true) and
/* 8.6+ logs also failed access attempt which generate some noise */
not event.outcome == "failure"