Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0085 — Credential Dumping from SAM via Registry Dump and Local File Access
DET0085

Credential Dumping from SAM via Registry Dump and Local File Access

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0235 Analytic 0235
Windows

An adversary running with SYSTEM-level privileges executes commands or accesses registry keys to dump the SAM hive or directly reads sensitive local files from the config directory. This behavior often involves sequential access to HKLM\SAM, HKLM\SYSTEM, and creation of .save or .dmp files, enabling offline hash extraction.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=2
[CommandLinePattern] Detectable variations include `reg save`, `reg.exe save`, or PowerShell equivalents for dumping SAM/SYSTEM hives.
[TargetFilePath] Defenders can tune based on dump file path patterns (e.g., `%TEMP%\sam.save`, `C:\Users\Public\*.dmp`).
[RegistryPath] Tune for HKLM\SAM, HKLM\SYSTEM or access via direct \Device\Harddisk paths.
[TimeWindow] Temporal gap between SAM and SYSTEM hive dumping can be tuned (e.g., 3 minutes).
[ParentProcessName] Useful for suppressing known-good access (e.g., backup tools).

Detected Techniques

1

Details

MITRE ID
DET0085
STIX ID
x-mitre-detection-strategy--13c88a68-15e3-45e5-958b-82fe7b948561
Analytics
1
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.