{"id":"T1003.002","name":"Security Account Manager","url":"https://attack.mitre.org/techniques/T1003/002","tactics":["credential-access"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0085","stix_id":"x-mitre-detection-strategy--13c88a68-15e3-45e5-958b-82fe7b948561","name":"Credential Dumping from SAM via Registry Dump and Local File Access","url":"https://attack.mitre.org/detectionstrategies/DET0085","analytics":[{"id":"AN0235","stix_id":"x-mitre-analytic--8c881d82-21c3-482c-8895-c240360eec8e","name":"Analytic 0235","description":"An adversary running with SYSTEM-level privileges executes commands or accesses registry keys to dump the SAM hive or directly reads sensitive local files from the config directory. This behavior often involves sequential access to HKLM\\SAM, HKLM\\SYSTEM, and creation of .save or .dmp files, enabling offline hash extraction.","url":"https://attack.mitre.org/detectionstrategies/DET0085#AN0235","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=2","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"CommandLinePattern","description":"Detectable variations include `reg save`, `reg.exe save`, or PowerShell equivalents for dumping SAM/SYSTEM hives."},{"field":"TargetFilePath","description":"Defenders can tune based on dump file path patterns (e.g., `%TEMP%\\sam.save`, `C:\\Users\\Public\\*.dmp`)."},{"field":"RegistryPath","description":"Tune for HKLM\\SAM, HKLM\\SYSTEM or access via direct \\Device\\Harddisk paths."},{"field":"TimeWindow","description":"Temporal gap between SAM and SYSTEM hive dumping can be tuned (e.g., 3 minutes)."},{"field":"ParentProcessName","description":"Useful for suppressing known-good access (e.g., backup tools)."}],"live":true,"detection_strategies":["DET0085"],"techniques":["T1003.002"]}],"live":true,"version":"1.0","techniques":["T1003.002"]}],"sigma_rules":[{"id":"0685b176-c816-4837-8e7b-1216f346636b","title":"HackTool - Quarks PwDump Execution","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-09-05","modified":"2023-02-05","description":"Detects usage of the Quarks PwDump tool via commandline arguments","references":["https://github.com/quarkslab/quarkspwdump","https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/seedworm-apt-iran-middle-east"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.002"],"path":"rules/windows/process_creation/proc_creation_win_hktl_quarks_pwdump.yml","techniques":["T1003.002"],"cves":[]},{"id":"06d71506-7beb-4f22-8888-e2e5e2ca7fd8","title":"Mimikatz Use","author":"Florian Roth (Nextron Systems), David ANDRE (additional keywords)","status":"test","level":"high","date":"2017-01-10","modified":"2022-01-05","description":"This method detects mimikatz keywords in different Eventlogs (some of them only appear in older Mimikatz version that are however still used by different threat groups)","references":["https://tools.thehacker.recipes/mimikatz/modules"],"logsource":{"product":"windows"},"tags":["attack.s0002","attack.lateral-movement","attack.credential-access","car.2013-07-001","car.2019-04-004","attack.t1003.002","attack.t1003.004","attack.t1003.001","attack.t1003.006"],"path":"rules/windows/builtin/win_alert_mimikatz_keywords.yml","techniques":["T1003.002","T1003.004","T1003.001","T1003.006"],"cves":[]},{"id":"11b1ed55-154d-4e82-8ad7-83739298f720","title":"NTDS.DIT Creation By Uncommon Process","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-01-11","modified":"2022-07-14","description":"Detects creation of a file named \"ntds.dit\" (Active Directory Database) by an uncommon process or a process located in a suspicious directory","references":["https://stealthbits.com/blog/extracting-password-hashes-from-the-ntds-dit-file/","https://adsecurity.org/?p=2398"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.credential-access","attack.t1003.002","attack.t1003.003"],"path":"rules/windows/file/file_event/file_event_win_ntds_dit_uncommon_process.yml","techniques":["T1003.002","T1003.003"],"cves":[]},{"id":"1af57a4b-460a-4738-9034-db68b880c665","title":"PowerShell SAM Copy","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-07-29","modified":"2023-01-06","description":"Detects suspicious PowerShell scripts accessing SAM hives","references":["https://twitter.com/splinter_code/status/1420546784250769408"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.002"],"path":"rules/windows/process_creation/proc_creation_win_powershell_sam_access.yml","techniques":["T1003.002"],"cves":[]},{"id":"252902e3-5830-4cf6-bf21-c22083dfd5cf","title":"Possible Impacket SecretDump Remote Activity","author":"Samir Bousseaden, wagga","status":"test","level":"high","date":"2019-04-03","modified":"2022-08-11","description":"Detect AD credential dumping using impacket secretdump HKTL","references":["https://web.archive.org/web/20230329153811/https://blog.menasec.net/2019/02/threat-huting-10-impacketsecretdump.html"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.t1003.002","attack.t1003.004","attack.t1003.003"],"path":"rules/windows/builtin/security/win_security_impacket_secretdump.yml","techniques":["T1003.002","T1003.004","T1003.003"],"cves":[]},{"id":"2e69f167-47b5-4ae7-a390-47764529eff5","title":"Transferring Files with Credential Data via Network Shares - Zeek","author":"@neu5ron, Teymur Kheirkhabarov, oscd.community","status":"test","level":"medium","date":"2020-04-02","modified":"2021-11-27","description":"Transferring files with well-known filenames (sensitive files with credential data) using network shares","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"zeek","service":"smb_files"},"tags":["attack.credential-access","attack.t1003.002","attack.t1003.001","attack.t1003.003"],"path":"rules/network/zeek/zeek_smb_converted_win_transferring_files_with_credential_data.yml","techniques":["T1003.002","T1003.001","T1003.003"],"cves":[]},{"id":"2fcda7e2-8c57-4904-86ac-37fc3157e09d","title":"Sensitive File Dump Via Print.EXE","author":"Ayush Anand (Securityinbits)","status":"test","level":"high","date":"2026-04-28","modified":null,"description":"Detects the abuse of the Print.exe utility for credential harvesting which involves using Print.Exe to copy sensitive files such as ntds.dit, SAM, SECURITY, or SYSTEM from the Windows directory in order to extract credentials, locally or remotely.\n","references":["https://www.microsoft.com/en-us/security/blog/2026/02/06/active-exploitation-solarwinds-web-help-desk/","https://www.huntress.com/blog/credential-theft-expanding-your-reach-pt-2","https://lolbas-project.github.io/lolbas/Binaries/Print/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.stealth","attack.t1003.003","attack.t1003.002","attack.t1218"],"path":"rules/windows/process_creation/proc_creation_win_print_dump_sensitive_files.yml","techniques":["T1003.003","T1003.002","T1218"],"cves":[]},{"id":"39f919f3-980b-4e6f-a975-8af7e507ef2b","title":"Critical Hive In Suspicious Location Access Bits Cleared","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-05-15","modified":"2024-01-18","description":"Detects events from the Kernel-General ETW indicating that the access bits of a hive with a system like hive name located in the temp directory have been reset.\nThis occurs when an application tries to access a hive and the hive has not be recognized since the last 7 days (by default).\nRegistry hive dumping utilities such as QuarksPwDump were seen emitting this behavior.\n","references":["https://github.com/nasbench/Misc-Research/blob/b20da2336de0f342d31ef4794959d28c8d3ba5ba/ETW/Microsoft-Windows-Kernel-General.md"],"logsource":{"product":"windows","service":"system"},"tags":["attack.credential-access","attack.t1003.002"],"path":"rules/windows/builtin/system/microsoft_windows_kernel_general/win_system_susp_critical_hive_location_access_bits_cleared.yml","techniques":["T1003.002"],"cves":[]},{"id":"40b19fa6-d835-400c-b301-41f3a2baacaf","title":"VolumeShadowCopy Symlink Creation Via Mklink","author":"Teymur Kheirkhabarov, oscd.community","status":"stable","level":"high","date":"2019-10-22","modified":"2023-03-06","description":"Shadow Copies storage symbolic link creation using operating systems utilities","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.002","attack.t1003.003"],"path":"rules/windows/process_creation/proc_creation_win_cmd_mklink_shadow_copies_access_symlink.yml","techniques":["T1003.002","T1003.003"],"cves":[]},{"id":"4976aa50-8f41-45c6-8b15-ab3fc10e79ed","title":"Credential Dumping Tools Service Execution - System","author":"Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community","status":"test","level":"high","date":"2017-03-05","modified":"2022-11-29","description":"Detects well-known credential dumping tools execution via service execution events","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","service":"system"},"tags":["attack.credential-access","attack.execution","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005","attack.t1003.006","attack.t1569.002","attack.s0005"],"path":"rules/windows/builtin/system/service_control_manager/win_system_mal_creddumper.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005","T1003.006","T1569.002"],"cves":[]},{"id":"4e87b8e2-2ee9-4b2a-a715-4727d297ece0","title":"Potential SAM Database Dump","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-02-11","modified":"2023-01-05","description":"Detects the creation of files that look like exports of the local SAM (Security Account Manager)","references":["https://github.com/search?q=CVE-2021-36934","https://web.archive.org/web/20210725081645/https://github.com/cube0x0/CVE-2021-36934","https://www.google.com/search?q=%22reg.exe+save%22+sam","https://github.com/HuskyHacks/ShadowSteal","https://github.com/FireFart/hivenightmare"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.credential-access","attack.t1003.002"],"path":"rules/windows/file/file_event/file_event_win_sam_dump.yml","techniques":["T1003.002"],"cves":[]},{"id":"5aad0995-46ab-41bd-a9ff-724f41114971","title":"Esentutl Volume Shadow Copy Service Keys","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)","status":"test","level":"high","date":"2020-10-20","modified":"2022-12-25","description":"Detects the volume shadow copy service initialization and processing via esentutl. Registry keys such as HKLM\\\\System\\\\CurrentControlSet\\\\Services\\\\VSS\\\\Diag\\\\VolSnap\\\\Volume are captured.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1003.002/T1003.002.md#atomic-test-3---esentutlexe-sam-copy"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.credential-access","attack.t1003.002"],"path":"rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml","techniques":["T1003.002"],"cves":[]},{"id":"78cc2dd2-7d20-4d32-93ff-057084c38b93","title":"Antivirus - Password Dumper Signature","author":"Florian Roth (Nextron Systems), Arnim Rupp","status":"stable","level":"critical","date":"2018-09-09","modified":"2026-06-15","description":"Detects a highly relevant Antivirus alert that reports password dumpers and stealers.\nThis event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place and check if passwords need to be reset.\n","references":["https://www.nextron-systems.com/?s=antivirus","https://www.virustotal.com/gui/file/5fcda49ee7f202559a6cbbb34edb65c33c9a1e0bde9fa2af06a6f11b55ded619","https://www.virustotal.com/gui/file/a4edfbd42595d5bddb442c82a02cf0aaa10893c1bf79ea08b9ce576f82749448"],"logsource":{"category":"antivirus"},"tags":["attack.credential-access","attack.t1003","attack.t1558","attack.t1003.001","attack.t1003.002"],"path":"rules/category/antivirus/av_password_dumper.yml","techniques":["T1003","T1558","T1003.001","T1003.002"],"cves":[]},{"id":"847def9e-924d-4e90-b7c4-5f581395a2b4","title":"HackTool - QuarksPwDump Dump File","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2018-02-10","modified":"2024-06-27","description":"Detects a dump file written by QuarksPwDump password dumper","references":["https://jpcertcc.github.io/ToolAnalysisResultSheet/details/QuarksPWDump.htm"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.credential-access","attack.t1003.002"],"path":"rules/windows/file/file_event/file_event_win_hktl_quarkspw_filedump.yml","techniques":["T1003.002"],"cves":[]},{"id":"882fbe50-d8d7-4e29-ae80-0648a8556866","title":"Crash Dump Created By Operating System","author":"Jason Mull","status":"experimental","level":"medium","date":"2025-05-12","modified":null,"description":"Detects \"BugCheck\" errors indicating the system rebooted due to a crash, capturing the bugcheck code, dump file path, and report ID.","references":["https://www.sans.edu/cyber-research/from-crash-compromise-unlocking-potential-windows-crash-dumps-offensive-security/","https://jasonmull.com/articles/offensive/2025-05-12-windows-crash-dumps-offensive-security/"],"logsource":{"product":"windows","service":"system"},"tags":["attack.credential-access","attack.collection","attack.t1003.002","attack.t1005"],"path":"rules/windows/builtin/system/microsoft_windows_wer_systemerrorreporting/win_system_crash_dump_created.yml","techniques":["T1003.002","T1005"],"cves":[]},{"id":"8a1b2c3d-4e5f-6789-abcd-ef1234567890","title":"PUA - Memory Dump Mount Via MemProcFS","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-27","modified":null,"description":"Detects execution of MemProcFS a memory forensics tool with the '-device' parameter.\nMemProcFS mounts physical memory as a virtual file system, allowing direct access to process memory and system structures.\nThreat actors were seen abusing this utility to mount memory dumps and then extract sensitive information from processes like LSASS or extract registry hives to obtain credentials, LSA secrets, SAM data, and cached domain credentials.\nMemProcFS usage that is not part of authorized forensic analysis should be treated as suspicious and warrants further investigation.\n","references":["https://github.com/ufrisk/MemProcFS","https://0xdf.gitlab.io/2024/10/05/htb-freelancer.html#","https://www.huntress.com/blog/curling-for-data-a-dive-into-a-threat-actors-malicious-ttps"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003","attack.t1003.001","attack.t1003.004","attack.t1003.002"],"path":"rules/windows/process_creation/proc_creation_win_pua_memprocfs.yml","techniques":["T1003","T1003.001","T1003.004","T1003.002"],"cves":[]},{"id":"8fbf3271-1ef6-4e94-8210-03c2317947f6","title":"Cred Dump Tools Dropped Files","author":"Teymur Kheirkhabarov, oscd.community","status":"test","level":"high","date":"2019-11-01","modified":"2025-10-25","description":"Files with well-known filenames (parts of credential dump software or files produced by them) creation","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.credential-access","attack.t1003.001","attack.t1003.002","attack.t1003.003","attack.t1003.004","attack.t1003.005"],"path":"rules/windows/file/file_event/file_event_win_cred_dump_tools_dropped_files.yml","techniques":["T1003.001","T1003.002","T1003.003","T1003.004","T1003.005"],"cves":[]},{"id":"910ab938-668b-401b-b08c-b596e80fdca5","title":"Transferring Files with Credential Data via Network Shares","author":"Teymur Kheirkhabarov, oscd.community","status":"test","level":"medium","date":"2019-10-22","modified":"2025-07-11","description":"Transferring files with well-known filenames (sensitive files with credential data) using network shares","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.t1003.002","attack.t1003.001","attack.t1003.003"],"path":"rules/windows/builtin/security/win_security_transf_files_with_cred_data_via_network_shares.yml","techniques":["T1003.002","T1003.001","T1003.003"],"cves":[]},{"id":"92dae1ed-1c9d-4eff-a567-33acbd95b00e","title":"Possible Impacket SecretDump Remote Activity - Zeek","author":"Samir Bousseaden, @neu5ron","status":"test","level":"high","date":"2020-03-19","modified":"2021-11-27","description":"Detect AD credential dumping using impacket secretdump HKTL. Based on the SIGMA rules/windows/builtin/win_impacket_secretdump.yml","references":["https://web.archive.org/web/20230329153811/https://blog.menasec.net/2019/02/threat-huting-10-impacketsecretdump.html"],"logsource":{"product":"zeek","service":"smb_files"},"tags":["attack.credential-access","attack.t1003.002","attack.t1003.004","attack.t1003.003"],"path":"rules/network/zeek/zeek_smb_converted_win_impacket_secretdump.yml","techniques":["T1003.002","T1003.004","T1003.003"],"cves":[]},{"id":"961d0ba2-3eea-4303-a930-2cf78bbfcc5e","title":"HackTool - Credential Dumping Tools Named Pipe Created","author":"Teymur Kheirkhabarov, oscd.community","status":"test","level":"critical","date":"2019-11-01","modified":"2023-08-07","description":"Detects well-known credential dumping tools execution via specific named pipe creation","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment","https://image.slidesharecdn.com/zeronights2017kheirkhabarov-171118103000/75/hunting-for-credentials-dumping-in-windows-environment-57-2048.jpg?cb=1666035799"],"logsource":{"product":"windows","category":"pipe_created"},"tags":["attack.credential-access","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005"],"path":"rules/windows/pipe_created/pipe_created_hktl_generic_cred_dump_tools_pipes.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005"],"cves":[]},{"id":"a29808fd-ef50-49ff-9c7a-59a9b040b404","title":"HackTool - Pypykatz Credentials Dumping Activity","author":"frack113","status":"test","level":"high","date":"2022-01-05","modified":"2023-02-05","description":"Detects the usage of \"pypykatz\" to obtain stored credentials. Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database through Windows registry where the SAM database is stored","references":["https://github.com/skelsec/pypykatz","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1003.002/T1003.002.md#atomic-test-2---registry-parse-with-pypykatz"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.002"],"path":"rules/windows/process_creation/proc_creation_win_hktl_pypykatz.yml","techniques":["T1003.002"],"cves":[]},{"id":"a642964e-bead-4bed-8910-1bb4d63e3b4d","title":"HackTool - Mimikatz Execution","author":"Teymur Kheirkhabarov, oscd.community, David ANDRE (additional keywords), Tim Shelton","status":"test","level":"high","date":"2019-10-22","modified":"2023-02-21","description":"Detection well-known mimikatz command line arguments","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment","https://tools.thehacker.recipes/mimikatz/modules"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005","attack.t1003.006"],"path":"rules/windows/process_creation/proc_creation_win_hktl_mimikatz_command_line.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005","T1003.006"],"cves":[]},{"id":"b17ea6f7-6e90-447e-a799-e6c0a493d6ce","title":"Shadow Copies Creation Using Operating Systems Utilities","author":"Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community","status":"test","level":"medium","date":"2019-10-22","modified":"2022-11-10","description":"Shadow Copies creation using operating systems utilities, possible credential access","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/tutorial-for-ntds-goodness-vssadmin-wmis-ntdsdit-system/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003","attack.t1003.002","attack.t1003.003"],"path":"rules/windows/process_creation/proc_creation_win_susp_shadow_copies_creation.yml","techniques":["T1003","T1003.002","T1003.003"],"cves":[]},{"id":"e7be6119-fc37-43f0-ad4f-1f3f99be2f9f","title":"Copying Sensitive Files with Credential Data","author":"Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community","status":"test","level":"high","date":"2019-10-22","modified":"2024-06-04","description":"Files with well-known filenames (sensitive files with credential data) copying","references":["https://room362.com/post/2013/2013-06-10-volume-shadow-copy-ntdsdit-domain-hashes-remotely-part-1/","https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://github.com/LOLBAS-Project/LOLBAS/blob/2cc01b01132b5c304027a658c698ae09dd6a92bf/yml/OSBinaries/Esentutl.yml"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.002","attack.t1003.003","car.2013-07-001","attack.s0404"],"path":"rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml","techniques":["T1003.002","T1003.003"],"cves":[]},{"id":"e9faba72-4974-4ab2-a4c5-46e25ad59e9b","title":"VSSAudit Security Event Source Registration","author":"Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR)","status":"test","level":"informational","date":"2020-10-20","modified":"2022-04-28","description":"Detects the registration of the security event source VSSAudit. It would usually trigger when volume shadow copy operations happen.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1003.002/T1003.002.md#atomic-test-3---esentutlexe-sam-copy"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.t1003.002"],"path":"rules/windows/builtin/security/win_security_vssaudit_secevent_source_registration.yml","techniques":["T1003.002"],"cves":[]},{"id":"f0d1feba-4344-4ca9-8121-a6c97bd6df52","title":"Credential Dumping Tools Service Execution - Security","author":"Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community","status":"test","level":"high","date":"2017-03-05","modified":"2022-11-29","description":"Detects well-known credential dumping tools execution via service execution events","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.execution","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005","attack.t1003.006","attack.t1569.002","attack.s0005"],"path":"rules/windows/builtin/security/win_security_mal_creddumper.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005","T1003.006","T1569.002"],"cves":[]},{"id":"f512acbf-e662-4903-843e-97ce4652b740","title":"Volume Shadow Copy Mount","author":"Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR)","status":"test","level":"low","date":"2020-10-20","modified":"2022-12-25","description":"Detects volume shadow copy mount via Windows event log","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1003.002/T1003.002.md#atomic-test-3---esentutlexe-sam-copy"],"logsource":{"product":"windows","service":"system"},"tags":["attack.credential-access","attack.t1003.002"],"path":"rules/windows/builtin/system/microsoft_windows_ntfs/win_system_volume_shadow_copy_mount.yml","techniques":["T1003.002"],"cves":[]},{"id":"fd877b94-9bb5-4191-bb25-d79cbd93c167","title":"Dumping of Sensitive Hives Via Reg.EXE","author":"Teymur Kheirkhabarov, Endgame, JHasenbusch, Daniil Yugoslavskiy, oscd.community, frack113","status":"test","level":"high","date":"2019-10-22","modified":"2023-12-13","description":"Detects the usage of \"reg.exe\" in order to dump sensitive registry hives. This includes SAM, SYSTEM and SECURITY hives.","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment","https://eqllib.readthedocs.io/en/latest/analytics/aed95fc6-5e3f-49dc-8b35-06508613f979.html","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1003/T1003.md","https://www.wietzebeukema.nl/blog/windows-command-line-obfuscation","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.002","attack.t1003.004","attack.t1003.005","car.2013-07-001"],"path":"rules/windows/process_creation/proc_creation_win_reg_dumping_sensitive_hives.yml","techniques":["T1003.002","T1003.004","T1003.005"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}