Title:
PowerShell SAM Copy
Status:
test
Description:Detects suspicious PowerShell scripts accessing SAM hives
References:
-https://twitter.com/splinter_code/status/1420546784250769408
Author: Florian Roth (Nextron Systems)
Date: 2021-07-29
modified:2023-01-06
Tags:
- -'attack.credential-access'
- -'attack.t1003.002'
Logsource:
- category: process_creation
- product: windows
Detection:
selection_1:
CommandLine|contains|all:
-'\HarddiskVolumeShadowCopy'
-'System32\config\sam'
selection_2:
CommandLine|contains:
-'Copy-Item'
-'cp $_.'
-'cpi $_.'
-'copy $_.'
-'.File]::Copy('
condition:
all of selection*
Falsepositives:
-Some rare backup scenarios
-PowerShell scripts fixing HiveNightmare / SeriousSAM ACLs
Level:
high