Security Account Manager

T1003.002

Sub-technique of T1003 OS Credential Dumping.View on attack.mitre.org

About this technique

Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the net user command. Enumerating the SAM database requires SYSTEM level access.

A number of tools can be used to retrieve the SAM file through in-memory techniques:

* pwdumpx.exe
* gsecdump
* Mimikatz
* secretsdump.py

Alternatively, the SAM can be extracted from the Registry with Reg:

* reg save HKLM\sam sam
* reg save HKLM\system system

Creddump7 can then be used to process the SAM database locally to retrieve hashes.

Notes:

* RID 500 account is the local, built-in administrator.
* RID 501 is the guest account.
* User accounts start with a RID of 1,000+.

Detection rules40

Rules on DetectionCode tagged with T1003.002.

Sigma28

RuleLevelLog source
Antivirus - Password Dumper SignaturecriticalNULL / antivirus
HackTool - Credential Dumping Tools Named Pipe Createdcriticalwindows / pipe_created
HackTool - QuarksPwDump Dump Filecriticalwindows / file_event
Copying Sensitive Files with Credential Datahighwindows / process_creation
Cred Dump Tools Dropped Fileshighwindows / file_event
Credential Dumping Tools Service Execution - Securityhighwindows / NULL
Credential Dumping Tools Service Execution - Systemhighwindows / NULL
Critical Hive In Suspicious Location Access Bits Clearedhighwindows / NULL
Dumping of Sensitive Hives Via Reg.EXEhighwindows / process_creation
Esentutl Volume Shadow Copy Service Keyshighwindows / registry_event
HackTool - Mimikatz Executionhighwindows / process_creation
HackTool - Pypykatz Credentials Dumping Activityhighwindows / process_creation
HackTool - Quarks PwDump Executionhighwindows / process_creation
Mimikatz Usehighwindows / NULL
NTDS.DIT Creation By Uncommon Processhighwindows / file_event

Splunk12

RuleTypeRiskData source
Attempted Credential Dump From Registry via Reg exeTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Azure AD Privileged Authentication Administrator Role AssignedTTPNULLAzure Active Directory Add member to role
Azure AD Privileged Graph API Permission AssignedTTPNULLAzure Active Directory Update application
Detect Copy of ShadowCopy with Script Block LoggingTTPNULLPowershell Script Block Logging 4104
Esentutl SAM CopyHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Excel Spawning PowerShellTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Excel Spawning Windows Script HostTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Extraction of Registry HivesTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
O365 Privileged Graph API Permission AssignedTTPNULLO365 Update application.
SAM Database File Access AttemptHuntingNULLWindows Event Log Security 4663
Windows Rapid Authentication On Multiple HostsTTPNULLWindows Event Log Security 4624
Windows Sensitive Registry Hive Dump Via CommandLineTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups14

Software15

Campaigns7

Procedure examples36

Groups14

Used byProcedure example
GroupAgrius

Agrius dumped the SAM file on victim machines to capture credentials.

GroupAPT29

APT29 has used the `reg save` command to save registry hives.

GroupAPT41

APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the reg save command or by exploiting volume shadow copies.

GroupAPT5

APT5 has copied and exfiltrated the SAM Registry hive from targeted systems.

GroupDaggerfly

Daggerfly used Reg to dump the Security Account Manager (SAM) hive from victim machines for follow-on credential extraction.

GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes.

GroupEmber Bear

Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as reg save.

GroupFIN13

FIN13 has extracted the SAM and SYSTEM registry hives using the `reg.exe` binary for obtaining password hashes from a compromised machine.

View all 14 groups examples

Software15

Used byProcedure example
MalwareCobalt Strike

Cobalt Strike can recover hashed passwords.

MalwareCosmicDuke

CosmicDuke collects Windows account hashes.

MalwareCozyCar

Password stealer and NTLM stealer modules in CozyCar harvest stored credentials from the victim, including credentials used as part of Windows NTLM user authentication.

ToolCrackMapExec

CrackMapExec can dump usernames and hashed passwords from the SAM.

ToolFgdump

Fgdump can dump Windows password hashes.

Toolgsecdump

gsecdump can dump Windows password hashes from the SAM.

MalwareHOPLIGHT

HOPLIGHT has the capability to harvest credentials and passwords from the SAM database.

MalwareIceApple

IceApple's Credential Dumper module can dump encrypted password hashes from SAM registry keys, including `HKLM\SAM\SAM\Domains\Account\F` and `HKLM\SAM\SAM\Domains\Account\Users\*\V`.

View all 15 software examples

Campaigns7

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had stolen Security Account Manager (SAM) and SYSTEM registry hives.

CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used the following commands to dump SAM, SYSTEM, and SECURITY hives: reg save hklm\sam, reg save hklm\system, and reg save hklm\security.

CampaignC0017

During C0017, APT41 copied the `SAM` and `SYSTEM` Registry hives for credential harvesting.

CampaignFrostyGoop Incident

During FrostyGoop Incident, the adversary retrieved the contents of the Security Account Manager (SAM) hive in the victim environment for credential capture.

CampaignNight Dragon

During Night Dragon, threat actors dumped account hashes using gsecdump.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors leveraged a custom tool to dump OS credentials and used following commands: `reg save HKLM\\SYSTEM system.hiv`, `reg save HKLM\\SAM sam.hiv`, and `reg save HKLM\\SECURITY security.hiv`, to dump SAM, SYSTEM and SECURITY hives.

CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used `reg save` to retrieve credentials from the Security Account Manager (SAM) database.

References1

  1. GitHub Creddump7 Open source
    Flathers, R. (2018, February 19). creddump7. Retrieved April 11, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.