PowerShell SAM Copy

 Original Source: [Sigma source]
Title: PowerShell SAM Copy
Status: test
Description:Detects suspicious PowerShell scripts accessing SAM hives
References:
  -https://twitter.com/splinter_code/status/1420546784250769408
Author: Florian Roth (Nextron Systems)
Date: 2021-07-29
modified:2023-01-06
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_1:
    CommandLine|contains|all:
      -'\HarddiskVolumeShadowCopy'
      -'System32\config\sam'

  selection_2:
    CommandLine|contains:
      -'Copy-Item'
      -'cp $_.'
      -'cpi $_.'
      -'copy $_.'
      -'.File]::Copy('

  condition:all of selection*
Falsepositives:
  -Some rare backup scenarios
  -PowerShell scripts fixing HiveNightmare / SeriousSAM ACLs
Level: high