Potential SAM Database Dump

 Original Source: [Sigma source]
Title: Potential SAM Database Dump
Status: test
Description:Detects the creation of files that look like exports of the local SAM (Security Account Manager)
References:
  -https://github.com/search?q=CVE-2021-36934
  -https://web.archive.org/web/20210725081645/https://github.com/cube0x0/CVE-2021-36934
  -https://www.google.com/search?q=%22reg.exe+save%22+sam
  -https://github.com/HuskyHacks/ShadowSteal
  -https://github.com/FireFart/hivenightmare
Author: Florian Roth (Nextron Systems)
Date: 2022-02-11
modified:2023-01-05
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.002'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    - TargetFilename|endswith:
      - '\Temp\sam'
      - '\sam.sav'
      - '\Intel\sam'
      - '\sam.hive'
      - '\Perflogs\sam'
      - '\ProgramData\sam'
      - '\Users\Public\sam'
      - '\AppData\Local\sam'
      - '\AppData\Roaming\sam'
      - '_ShadowSteal.zip'
      - '\Documents\SAM.export'
      - ':\sam'
    - TargetFilename|contains:
      - '\hive_sam_'
      - '\sam.save'
      - '\sam.export'
      - '\~reg_sam.save'
      - '\sam_backup'
      - '\sam.bck'
      - '\sam.backup'
  condition:selection
Falsepositives:
  -Rare cases of administrative activity
Level: high