Cross-source coverage

T1003.002 / ATT&CK

OS Credential Dumping: Security Account Manager

58 rules across 5 sources.

From MITRE ATT&CK 19.2

Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the net user command. Enumerating the SAM database requires SYSTEM level access.

A number of tools can be used to retrieve the SAM file through in-memory techniques:

Alternatively, the SAM can be extracted from the Registry with Reg:

  • reg save HKLM\sam sam
  • reg save HKLM\system system

Creddump7 can then be used to process the SAM database locally to retrieve hashes.

Notes:

  • RID 500 account is the local, built-in administrator.
  • RID 501 is the guest account.
  • User accounts start with a RID of 1,000+.
Platforms
Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmon

How MITRE says to detect it DET0085

Credential Dumping from SAM via Registry Dump and Local File Access

Windows Analytic 0235

An adversary running with SYSTEM-level privileges executes commands or accesses registry keys to dump the SAM hive or directly reads sensitive local files from the config directory. This behavior often involves sequential access to HKLM\SAM, HKLM\SYSTEM, and creation of.save or.dmp files, enabling offline hash extraction.

  • WinEventLog:Security EventCode=4688
  • WinEventLog:Sysmon EventCode=13, 14
  • WinEventLog:Sysmon EventCode=11
  • WinEventLog:Sysmon EventCode=2

SigmaHQ/sigma

28 rules
Detection Severity Format
Antivirus - Password Dumper Signature Critical Sigma
HackTool - Credential Dumping Tools Named Pipe Created Critical Sigma
HackTool - QuarksPwDump Dump File Critical Sigma
Copying Sensitive Files with Credential Data High Sigma
Cred Dump Tools Dropped Files High Sigma
Credential Dumping Tools Service Execution - Security High Sigma
Credential Dumping Tools Service Execution - System High Sigma
Critical Hive In Suspicious Location Access Bits Cleared High Sigma
Dumping of Sensitive Hives Via Reg.EXE High Sigma
Esentutl Volume Shadow Copy Service Keys High Sigma

+ 18 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

11 rules
Detection Severity Format
Potential Invoke-Mimikatz PowerShell Script Critical Elastic TOML
Credential Acquisition via Registry Hive Dumping High Elastic TOML
NTDS or SAM Database File Copied High Elastic TOML
Potential Credential Access via Trusted Developer Utility High Elastic TOML
Potential Remote Credential Access via Registry High Elastic TOML
PowerShell Invoke-NinjaCopy script High Elastic TOML
Sensitive Registry Hive Access via RegBack High Elastic TOML
NTDS Dump via Wbadmin Medium Elastic TOML
Suspicious Remote Registry Access via SeBackupPrivilege Medium Elastic TOML
Symbolic Link to Shadow Copy Created Medium Elastic TOML

+ 1 more from elastic/detection-rules → showing the 10 highest-severity

elastic/protections-artifacts

8 rules
Detection Severity Format
Potential Credential Access via Mimikatz Undefined Elastic TOML
Remote Access to Sensitive Registry Keys Undefined Elastic TOML
Security Account Manager (SAM) File Access Undefined Elastic TOML
Security Account Manager (SAM) Registry Access Undefined Elastic TOML
Sensitive File Access by an Unsigned Process Undefined Elastic TOML
Sensitive Hive Access via Registry Backup Undefined Elastic TOML
Suspicious Registry Hive Dump Undefined Elastic TOML
System BootKey Registry Access Undefined Elastic TOML

splunk/security_content

8 rules
Detection Severity Format
Azure AD Privileged Authentication Administrator Role Assigned Undefined SPL
Azure AD Privileged Graph API Permission Assigned Undefined SPL
Detect Copy of ShadowCopy with Script Block Logging Undefined SPL
Esentutl SAM Copy Undefined SPL
O365 Privileged Graph API Permission Assigned Undefined SPL
SAM Database File Access Attempt Undefined SPL
Windows Rapid Authentication On Multiple Hosts Undefined SPL
Windows Sensitive Registry Hive Dump Via CommandLine Undefined SPL

Wazuh Core Ruleset

3 rules
Detection Severity Format
Powershell used to copy SAM hive from VSS Critical Wazuh XML
Reg.exe used to dump SAM hive Critical Wazuh XML
Suspicious Powershell activity with VSS and Windows SAM hive Medium Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.