title: SAM Dump to AppData id: 839dd1e8-eda8-4834-8145-01beeee33acd status: experimental description: Detects suspicious SAM dump activity as cause by QuarksPwDump and other password dumpers tags: - attack.credential_access - attack.t1003 - attack.t1003.002 author: Florian Roth date: 2018/01/27 logsource: product: windows service: system definition: The source of this type of event is Kernel-General detection: selection: EventID: 16 Message: - '*\AppData\Local\Temp\SAM-*.dmp *' condition: selection falsepositives: - Penetration testing level: high