1200KM / simulation
T1003.002 Security Account Manager — Attack Simulation
Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the net user command. Enumerating the SAM database requires SYSTEM level access. A number of tools can be used to retrieve the SAM file through…
Technique description
Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the net user command. Enumerating the SAM database requires SYSTEM level access. A number of tools can be used to retrieve the SAM file through…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- WinPwn - Loot local Credentials - Dump SAM-File for NTLM Hashes
Procedure 0c0f5f06-166a-4f4d-bb4a-719df9a01dbb; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Dumping of SAM, creds, and secrets(Reg Export)
Procedure 21df41be-cdd8-4695-a650-c3981113aa3c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Registry dump of SAM, creds, and secrets
Procedure 5c2571d0-1572-416d-9676-812e64ca9f44; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- PowerDump Hashes and Usernames from Registry
Procedure 804f28fc-68fc-40da-b5a2-e9d0bce5c193; elevation required; cleanup not declared. Not executed or individually validated.
- dump volume shadow copy hives with System.IO.File
Procedure 9d77fed7-05f8-476e-a81b-8ff0472c64d0; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- esentutl.exe SAM copy
Procedure a90c2f4d-6726-444e-99d2-a00cd7c20480; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Registry parse with pypykatz
Procedure a96872b2-cbf3-46cf-8eb4-27e8c0e85263; elevation required; cleanup not declared. Not executed or individually validated.
- dump volume shadow copy hives with certutil
Procedure eeb9751a-d598-42d3-b11c-c122d9c3f6c7; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.