SAM Database Credential Dumping via reg save or NinjaCopy
Detects attempts to access or exfiltrate the Windows Security Account Manager (SAM) or SYSTEM registry hives, which are primary targets for extracting credential hashes. This rule identifies common attack vectors including native Windows registry utilities (reg.exe), PowerShell-based volume shadow copy techniques (Invoke-NinjaCopy), and known credential dumping tools like secretsdump (from the Impacket suite) executed via command line or interpreted through Python.
SentinelOne

