title: SAM Dump to AppData status: experimental description: Detects suspicious SAM dump activity as cause by QuarksPwDump and other password dumpers tags: - attack.credential_access - attack.t1003 author: Florian Roth logsource: product: windows service: system definition: The source of this type of event is Kernel-General detection: selection: EventID: 16 keywords: - '*\AppData\Local\Temp\SAM-*.dmp *' condition: all of them falsepositives: - Penetration testing level: high