This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential SAM Database Dump
Original Source:
[Sigma source]
Title:
Potential SAM Database Dump
Status:
test
Description:
Detects the creation of files that look like exports of the local SAM (Security Account Manager)
References:
-https://github.com/search?q=CVE-2021-36934
-https://web.archive.org/web/20210725081645/https://github.com/cube0x0/CVE-2021-36934
-https://www.google.com/search?q=%22reg.exe+save%22+sam
-https://github.com/HuskyHacks/ShadowSteal
-https://github.com/FireFart/hivenightmare
Author:
Florian Roth (Nextron Systems)
Date:
2022-02-11
modified:
2023-01-05
Tags:
-'attack.credential-access'
-'attack.t1003.002'
Logsource:
product: windows
category: file_event
Detection:
selection:
- TargetFilename|endswith
:
- '\Temp\sam'
- '\sam.sav'
- '\Intel\sam'
- '\sam.hive'
- '\Perflogs\sam'
- '\ProgramData\sam'
- '\Users\Public\sam'
- '\AppData\Local\sam'
- '\AppData\Roaming\sam'
- '_ShadowSteal.zip'
- '\Documents\SAM.export'
- ':\sam'
- TargetFilename|contains
:
- '\hive_sam_'
- '\sam.save'
- '\sam.export'
- '\~reg_sam.save'
- '\sam_backup'
- '\sam.bck'
- '\sam.backup'
condition
:
selection
Falsepositives:
-Rare cases of administrative activity
Level:
high