Windows reg.exe Registry Hive Dumping for SAM, SYSTEM, and SECURITY

Flags reg.exe command lines exporting or saving HKLM registry hives tied to SAM, SYSTEM, and SECURITY.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Teymur Kheirkhabarov, Endgame, JHasenbusch, Daniil Yugoslavskiy, oscd.community, frack113 (SigmaHQ), DRL 1.1
Published
2019-10-22
Updated
2026-07-30

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies Windows process executions of reg.exe where the command line includes hive-dump indicators for HKLM and references to the SYSTEM, SAM, and SECURITY hives. Attackers use reg.exe to collect sensitive credential material and secrets from the registry, so correlating reg.exe usage with hive-specific paths helps surface credential-access activity. Telemetry relies on process creation data including the executable image name and the full command line.

Related detections9 linkedT1003.002 — drag to rearrange
Windows Credential Dump Tool Artifacts Written to Disk via File Events
Windows Named Pipe Creation for Known Credential Dumping Tool Pipe Names
Windows Process Creation: Detect Mimikatz Tool and Module Command-Line Usage
Windows System Service Execution of Credential Dumping Tools (Service Control Manager Event 7045)
Windows Security EID 4697 Service Execution of Credential Dumping Tools
Windows PUA: MemProcFS memory dump mounting via -device
Zeek SMB Files: Impacket SecretDump Access to ADMIN$ and System32 .tmp Droppers
Windows Event Logs: Mimikatz Keyword Indicators
Credential Dumping via Reg Save of SAM Hive
Windows reg.exe Registry Hive Dumping for SAM, SYSTEM, and SECURITY
Pivot detection · T1003.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.