Cross-source coverage
T1003.002 / ATT&CK
OS Credential Dumping: Security Account Manager
58 rules across 5 sources.
From MITRE ATT&CK 19.2
Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the net user command. Enumerating the SAM database requires SYSTEM level access.
A number of tools can be used to retrieve the SAM file through in-memory techniques:
Alternatively, the SAM can be extracted from the Registry with Reg:
reg save HKLM\sam samreg save HKLM\system system
Creddump7 can then be used to process the SAM database locally to retrieve hashes.
Notes:
- RID 500 account is the local, built-in administrator.
- RID 501 is the guest account.
- User accounts start with a RID of 1,000+.
- Tactics
- Credential Access
- Platforms
- Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmon
How MITRE says to detect it DET0085
Credential Dumping from SAM via Registry Dump and Local File Access
Windows Analytic 0235
An adversary running with SYSTEM-level privileges executes commands or accesses registry keys to dump the SAM hive or directly reads sensitive local files from the config directory. This behavior often involves sequential access to HKLM\SAM, HKLM\SYSTEM, and creation of.save or.dmp files, enabling offline hash extraction.
WinEventLog:SecurityEventCode=4688WinEventLog:SysmonEventCode=13, 14WinEventLog:SysmonEventCode=11WinEventLog:SysmonEventCode=2
SigmaHQ/sigma
28 rules| Detection | Severity | Format |
|---|---|---|
| Antivirus - Password Dumper Signature | Critical | Sigma |
| HackTool - Credential Dumping Tools Named Pipe Created | Critical | Sigma |
| HackTool - QuarksPwDump Dump File | Critical | Sigma |
| Copying Sensitive Files with Credential Data | High | Sigma |
| Cred Dump Tools Dropped Files | High | Sigma |
| Credential Dumping Tools Service Execution - Security | High | Sigma |
| Credential Dumping Tools Service Execution - System | High | Sigma |
| Critical Hive In Suspicious Location Access Bits Cleared | High | Sigma |
| Dumping of Sensitive Hives Via Reg.EXE | High | Sigma |
| Esentutl Volume Shadow Copy Service Keys | High | Sigma |
+ 18 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
11 rules| Detection | Severity | Format |
|---|---|---|
| Potential Invoke-Mimikatz PowerShell Script | Critical | Elastic TOML |
| Credential Acquisition via Registry Hive Dumping | High | Elastic TOML |
| NTDS or SAM Database File Copied | High | Elastic TOML |
| Potential Credential Access via Trusted Developer Utility | High | Elastic TOML |
| Potential Remote Credential Access via Registry | High | Elastic TOML |
| PowerShell Invoke-NinjaCopy script | High | Elastic TOML |
| Sensitive Registry Hive Access via RegBack | High | Elastic TOML |
| NTDS Dump via Wbadmin | Medium | Elastic TOML |
| Suspicious Remote Registry Access via SeBackupPrivilege | Medium | Elastic TOML |
| Symbolic Link to Shadow Copy Created | Medium | Elastic TOML |
+ 1 more from elastic/detection-rules → showing the 10 highest-severity
elastic/protections-artifacts
8 rules| Detection | Severity | Format |
|---|---|---|
| Potential Credential Access via Mimikatz | Undefined | Elastic TOML |
| Remote Access to Sensitive Registry Keys | Undefined | Elastic TOML |
| Security Account Manager (SAM) File Access | Undefined | Elastic TOML |
| Security Account Manager (SAM) Registry Access | Undefined | Elastic TOML |
| Sensitive File Access by an Unsigned Process | Undefined | Elastic TOML |
| Sensitive Hive Access via Registry Backup | Undefined | Elastic TOML |
| Suspicious Registry Hive Dump | Undefined | Elastic TOML |
| System BootKey Registry Access | Undefined | Elastic TOML |
splunk/security_content
8 rules| Detection | Severity | Format |
|---|---|---|
| Azure AD Privileged Authentication Administrator Role Assigned | Undefined | SPL |
| Azure AD Privileged Graph API Permission Assigned | Undefined | SPL |
| Detect Copy of ShadowCopy with Script Block Logging | Undefined | SPL |
| Esentutl SAM Copy | Undefined | SPL |
| O365 Privileged Graph API Permission Assigned | Undefined | SPL |
| SAM Database File Access Attempt | Undefined | SPL |
| Windows Rapid Authentication On Multiple Hosts | Undefined | SPL |
| Windows Sensitive Registry Hive Dump Via CommandLine | Undefined | SPL |
Wazuh Core Ruleset
3 rules| Detection | Severity | Format |
|---|---|---|
| Powershell used to copy SAM hive from VSS | Critical | Wazuh XML |
| Reg.exe used to dump SAM hive | Critical | Wazuh XML |
| Suspicious Powershell activity with VSS and Windows SAM hive | Medium | Wazuh XML |