T1003.002 — Security Account Manager
T1003.002: Security Account Manager
MITRE ATT&CK® Enterprise technique
| Tactics | Credential Access |
| Platforms | Windows |
| Permissions required | — |
| Version | 1.1 |
| Parent technique | T1003 |
Description
Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the <code>net user</code> command. Enumerating the SAM database requires SYSTEM level access.
A number of tools can be used to retrieve the SAM file through in-memory techniques:
Alternatively, the SAM can be extracted from the Registry with Reg:
- <code>reg save HKLM\sam sam</code>
- <code>reg save HKLM\system system</code>
Creddump7 can then be used to process the SAM database locally to retrieve hashes.(Citation: GitHub Creddump7)
Notes:
- RID 500 account is the local, built-in administrator.
- RID 501 is the guest account.
- User accounts start with a RID of 1,000+.
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1003/002
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/