216.73.216.233

T1003.002: T1003.002

View on MITRE ATT&CK The MITRE Corporation · Published 11/02/2020 19:42 · Modified 15/04/2026 12:25

Essential information

MITRE technique ID
T1003.002
Confidence
100/100
Revoked
No
Published
11/02/2020 19:42
Modified
15/04/2026 12:25
Author / Source
The MITRE Corporation

Aliases

Security Account Manager

Platforms

windows

Description

Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the `net user` command. Enumerating the SAM database requires SYSTEM level access. A number of tools can be used to retrieve the SAM file through in-memory techniques: * pwdumpx.exe * [gsecdump](https://attack.mitre.org/software/S0008) * [Mimikatz](https://attack.mitre.org/software/S0002) * secretsdump.py Alternatively, the SAM can be extracted from the Registry with Reg: * `reg save HKLM\sam sam` * `reg save HKLM\system system` Creddump7 can then be used to process the SAM database locally to retrieve hashes.(Citation: GitHub Creddump7) Notes: * RID 500 account is the local, built-in administrator. * RID 501 is the guest account. * User accounts start with a RID of 1,000+.

Kill chain phases

Kill chainPhase
mitre-attack credential-access

Marking (TLP)

TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references