1200KM / detection
T1003.002 Security Account Manager — Detection Rules
Detection workspace for T1003.002 Security Account Manager: 28 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Antivirus Password Dumper Detection · stable · critical · {"category":"antivirus"}
- Possible Impacket SecretDump Remote Activity - Zeek · test · high · {"product":"zeek","service":"smb_files"}
- Transferring Files with Credential Data via Network Shares - Zeek · test · medium · {"product":"zeek","service":"smb_files"}
- Possible Impacket SecretDump Remote Activity · test · high · {"product":"windows","service":"security","definition":"The advanced audit policy setting \"Object Access > Audit Detailed File Share\" must be configured for Success/Failure"}
- Credential Dumping Tools Service Execution - Security · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Transferring Files with Credential Data via Network Shares · test · medium · {"product":"windows","service":"security"}
- VSSAudit Security Event Source Registration · test · informational · {"product":"windows","service":"security"}
- Critical Hive In Suspicious Location Access Bits Cleared · test · high · {"product":"windows","service":"system"}
- Volume Shadow Copy Mount · test · low · {"product":"windows","service":"system"}
- Crash Dump Created By Operating System · experimental · medium · {"product":"windows","service":"system"}
- Credential Dumping Tools Service Execution - System · test · high · {"product":"windows","service":"system"}
- Mimikatz Use · test · high · {"product":"windows"}
- Cred Dump Tools Dropped Files · test · high · {"category":"file_event","product":"windows"}
- HackTool - QuarksPwDump Dump File · test · critical · {"category":"file_event","product":"windows"}
- NTDS.DIT Creation By Uncommon Process · test · high · {"product":"windows","category":"file_event"}
- Potential SAM Database Dump · test · high · {"product":"windows","category":"file_event"}
- HackTool - Credential Dumping Tools Named Pipe Created · test · critical · {"product":"windows","category":"pipe_created","definition":"Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575"}
- VolumeShadowCopy Symlink Creation Via Mklink · stable · high · {"category":"process_creation","product":"windows"}
- Copying Sensitive Files with Credential Data · test · high · {"category":"process_creation","product":"windows"}
- HackTool - Mimikatz Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - Pypykatz Credentials Dumping Activity · test · high · {"category":"process_creation","product":"windows"}
- HackTool - Quarks PwDump Execution · test · high · {"category":"process_creation","product":"windows"}
- PowerShell SAM Copy · test · high · {"category":"process_creation","product":"windows"}
- Sensitive File Dump Via Print.EXE · test · high · {"category":"process_creation","product":"windows"}
- PUA - Memory Dump Mount Via MemProcFS · experimental · high · {"category":"process_creation","product":"windows"}
- Dumping of Sensitive Hives Via Reg.EXE · test · high · {"category":"process_creation","product":"windows"}
- Shadow Copies Creation Using Operating Systems Utilities · test · medium · {"category":"process_creation","product":"windows"}
- Esentutl Volume Shadow Copy Service Keys · test · high · {"category":"registry_event","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0085 Credential Dumping from SAM via Registry Dump and Local File Access
AN0235 Analytic 0235
An adversary running with SYSTEM-level privileges executes commands or accesses registry keys to dump the SAM hive or directly reads sensitive local files from the config directory. This behavior often involves sequential access to HKLM\SAM, HKLM\SYSTEM, and creation of .save or .dmp files, enabling offline hash extraction.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.