| Credential Dumping from SAM via Registry Dump and Local File Access - DET0085 (13c88a68-15e3-45e5-958b-82fe7b948561) |
Detection Strategies |
Security Account Manager - T1003.002 (1644e709-12d2-41e5-a60f-3470991f5011) |
Attack Pattern |
1 |
| Credential Dumping from SAM via Registry Dump and Local File Access - DET0085 (13c88a68-15e3-45e5-958b-82fe7b948561) |
Detection Strategies |
Analytic 0235 - AN0235 (8c881d82-21c3-482c-8895-c240360eec8e) |
Analytics |
1 |
| OS Credential Dumping - T1003 (0a3ead4e-6d47-4ccb-854c-a6a4f9d96b22) |
Attack Pattern |
Security Account Manager - T1003.002 (1644e709-12d2-41e5-a60f-3470991f5011) |
Attack Pattern |
2 |