title: SAM Dump to AppData id: 839dd1e8-eda8-4834-8145-01beeee33acd status: deprecated description: Detects suspicious SAM dump activity as cause by QuarksPwDump and other password dumpers author: Florian Roth (Nextron Systems) date: 2018/01/27 modified: 2024/01/18 tags: - attack.credential_access - attack.t1003.002 logsource: product: windows service: system definition: The source of this type of event is Kernel-General detection: selection: Provider_Name: Microsoft-Windows-Kernel-General EventID: 16 keywords: '|all': - '\AppData\Local\Temp\SAM-' - '.dmp' condition: selection and keywords falsepositives: - Unknown level: high