SAM Hive Access via offreg.dll Outside Registry Tools (PrettyPrague)
This rule detects instances where a process loads 'offreg.dll' (Offline Registry Library) and concurrently accesses the SAM (Security Account Manager) file. This is a common technique used by attackers to offline-extract local account hashes without using standard registry tools, potentially bypassing basic monitoring of 'reg.exe'.
Microsoft Sentinel (KQL)

