Sub-technique of T1003 OS Credential Dumping.View on attack.mitre.org
Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the net user command. Enumerating the SAM database requires SYSTEM level access.
A number of tools can be used to retrieve the SAM file through in-memory techniques:
* pwdumpx.exe
* gsecdump
* Mimikatz
* secretsdump.py
Alternatively, the SAM can be extracted from the Registry with Reg:
* reg save HKLM\sam sam
* reg save HKLM\system system
Creddump7 can then be used to process the SAM database locally to retrieve hashes.
Notes:
* RID 500 account is the local, built-in administrator.
* RID 501 is the guest account.
* User accounts start with a RID of 1,000+.
Rules on DetectionCode tagged with T1003.002.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Attempted Credential Dump From Registry via Reg exe | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Azure AD Privileged Authentication Administrator Role Assigned | TTP | NULL | Azure Active Directory Add member to role |
| Azure AD Privileged Graph API Permission Assigned | TTP | NULL | Azure Active Directory Update application |
| Detect Copy of ShadowCopy with Script Block Logging | TTP | NULL | Powershell Script Block Logging 4104 |
| Esentutl SAM Copy | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Excel Spawning PowerShell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Excel Spawning Windows Script Host | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Extraction of Registry Hives | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| O365 Privileged Graph API Permission Assigned | TTP | NULL | O365 Update application. |
| SAM Database File Access Attempt | Hunting | NULL | Windows Event Log Security 4663 |
| Windows Rapid Authentication On Multiple Hosts | TTP | NULL | Windows Event Log Security 4624 |
| Windows Sensitive Registry Hive Dump Via CommandLine | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAgrius | Agrius dumped the SAM file on victim machines to capture credentials. |
| GroupAPT29 | APT29 has used the `reg save` command to save registry hives. |
| GroupAPT41 | APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the |
| GroupAPT5 | APT5 has copied and exfiltrated the SAM Registry hive from targeted systems. |
| GroupDaggerfly | Daggerfly used Reg to dump the Security Account Manager (SAM) hive from victim machines for follow-on credential extraction. |
| GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. |
| GroupEmber Bear | Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as |
| GroupFIN13 | FIN13 has extracted the SAM and SYSTEM registry hives using the `reg.exe` binary for obtaining password hashes from a compromised machine. |
| Used by | Procedure example |
|---|---|
| MalwareCobalt Strike | Cobalt Strike can recover hashed passwords. |
| MalwareCosmicDuke | CosmicDuke collects Windows account hashes. |
| MalwareCozyCar | Password stealer and NTLM stealer modules in CozyCar harvest stored credentials from the victim, including credentials used as part of Windows NTLM user authentication. |
| ToolCrackMapExec | CrackMapExec can dump usernames and hashed passwords from the SAM. |
| ToolFgdump | Fgdump can dump Windows password hashes. |
| Toolgsecdump | gsecdump can dump Windows password hashes from the SAM. |
| MalwareHOPLIGHT | HOPLIGHT has the capability to harvest credentials and passwords from the SAM database. |
| MalwareIceApple | IceApple's Credential Dumper module can dump encrypted password hashes from SAM registry keys, including `HKLM\SAM\SAM\Domains\Account\F` and `HKLM\SAM\SAM\Domains\Account\Users\*\V`. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had stolen Security Account Manager (SAM) and SYSTEM registry hives. |
| CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used the following commands to dump SAM, SYSTEM, and SECURITY hives: |
| CampaignC0017 | During C0017, APT41 copied the `SAM` and `SYSTEM` Registry hives for credential harvesting. |
| CampaignFrostyGoop Incident | During FrostyGoop Incident, the adversary retrieved the contents of the Security Account Manager (SAM) hive in the victim environment for credential capture. |
| CampaignNight Dragon | During Night Dragon, threat actors dumped account hashes using gsecdump. |
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors leveraged a custom tool to dump OS credentials and used following commands: `reg save HKLM\\SYSTEM system.hiv`, `reg save HKLM\\SAM sam.hiv`, and `reg save HKLM\\SECURITY security.hiv`, to dump SAM, SYSTEM and SECURITY hives. |
| CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used `reg save` to retrieve credentials from the Security Account Manager (SAM) database. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.