Umbra Wiki technique technique/T1003.002
Back to wiki

T1003.002 — Security Account Manager

provenance: imported · ATT&CK: T1003.002

T1003.002: Security Account Manager

MITRE ATT&CK® Enterprise technique

Tactics Credential Access
Platforms Windows
Permissions required
Version 1.1
Parent technique T1003

Description

Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the <code>net user</code> command. Enumerating the SAM database requires SYSTEM level access.

A number of tools can be used to retrieve the SAM file through in-memory techniques:

Alternatively, the SAM can be extracted from the Registry with Reg:

  • <code>reg save HKLM\sam sam</code>
  • <code>reg save HKLM\system system</code>

Creddump7 can then be used to process the SAM database locally to retrieve hashes.(Citation: GitHub Creddump7)

Notes:

  • RID 500 account is the local, built-in administrator.
  • RID 501 is the guest account.
  • User accounts start with a RID of 1,000+.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1003/002
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/