SAM Registry Hive Dumping via reg.exe or Direct File Access (T1003.002)
Detects attempts to extract the Security Account Manager (SAM) database, either by using the 'reg save' utility to export registry hives containing the SAM or by directly creating/modifying the SAM file on disk outside of known legitimate system processes.
SentinelOne

