title: SAM Dump to AppData id: 839dd1e8-eda8-4834-8145-01beeee33acd status: test description: Detects suspicious SAM dump activity as cause by QuarksPwDump and other password dumpers author: Florian Roth date: 2018/01/27 modified: 2022/04/14 logsource: product: windows service: system definition: The source of this type of event is Kernel-General detection: selection: Provider_Name: Microsoft-Windows-Kernel-General EventID: 16 keywords: - '\AppData\Local\Temp\SAM-' - '.dmp' condition: selection and all of keywords falsepositives: - Unknown level: high tags: - attack.credential_access - attack.t1003.002