SAM/SYSTEM/SECURITY Registry Hive Dump via reg.exe or VSS
This rule detects attempts to acquire Windows credentials by accessing critical registry hives (SAM, SYSTEM, SECURITY) or their shadow copies. It looks for the use of 'reg save' to export hives, as well as direct file access to these hives or their shadow copy variations by non-standard system processes.
SentinelOne

