OS Credential Dumping: Security Account Manager T1003.002
Tactic: Credential Access
Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the net user command. Enumerating the SAM database requires SYSTEM level access.
Events covered
27 catalog events are tagged with this technique by at least one rule.
Authoring guide
Patterns shared across the 58 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (58 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (407 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (24 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 30 rules
- Antivirus Password Dumper Detection
- Backdoor introduction via registry permission change through WMI (DAMP)
- Copying Sensitive Files with Credential Data
- Crash Dump Created By Operating System
- Cred Dump Tools Dropped Files
- Credential Dumping Tools Service Execution - Security
- Credential Dumping Tools Service Execution - System
- Critical Hive In Suspicious Location Access Bits Cleared
- Dumping of Sensitive Hives Via Reg.EXE
- Esentutl Volume Shadow Copy Service Keys
- HackTool - Credential Dumping Tools Named Pipe Created
- HackTool - Mimikatz Execution
- HackTool - Pypykatz Credentials Dumping Activity
- HackTool - Quarks PwDump Execution
- HackTool - QuarksPwDump Dump File
- Mimikatz Use
- NTDS.DIT Creation By Uncommon Process
- Possible Impacket SecretDump Remote Activity
- Possible Impacket SecretDump Remote Activity - Zeek
- Potential SAM Database Dump
- PowerShell SAM Copy
- PUA - Memory Dump Mount Via MemProcFS
- Secretdump password dumping via SMB admin share
- Sensitive File Dump Via Print.EXE
- Shadow Copies Creation Using Operating Systems Utilities
- Transferring Files with Credential Data via Network Shares
- Transferring Files with Credential Data via Network Shares - Zeek
- Volume Shadow Copy Mount
- VolumeShadowCopy Symlink Creation Via Mklink
- VSSAudit Security Event Source Registration
Elastic 11 rules
- Credential Acquisition via Registry Hive Dumping
- NTDS Dump via Wbadmin
- NTDS or SAM Database File Copied
- Potential Credential Access via Trusted Developer Utility
- Potential Invoke-Mimikatz PowerShell Script
- Potential Remote Credential Access via Registry
- PowerShell Invoke-NinjaCopy script
- Sensitive Registry Hive Access via RegBack
- Suspicious Remote Registry Access via SeBackupPrivilege
- Symbolic Link to Shadow Copy Created
- Windows Registry File Creation in SMB Share
Splunk 17 rules
- Azure AD Privileged Authentication Administrator Role Assigned
- Azure AD Privileged Graph API Permission Assigned
- Detect Copy of ShadowCopy with Script Block Logging
- Esentutl Execution (PowerShell)
- Esentutl Execution (Sysmon)
- Esentutl Execution (Windows Event Log)
- Esentutl SAM Copy
- Mimikatz (Sysmon)
- Mimikatz (Windows Event Log)
- MultiDump.exe Execution (Sysmon)
- MultiDump.exe Execution (Windows Event Log)
- O365 Privileged Graph API Permission Assigned
- SAM Database File Access Attempt
- SAM, System, Security Files Accessed (Windows Event Log)
- SecretsDump Credential Harvest (Windows Event Log)
- Windows Rapid Authentication On Multiple Hosts
- Windows Sensitive Registry Hive Dump Via CommandLine