Windows Security Event 4656: SAM Registry Hive Key Handle Requested

Flags Windows handle requests to registry keys ending with \SAM using Security EventID 4656.

FreeReviewedSigma · High · v2
Product
windows
Service
security
Author
Roberto Rodriguez @Cyb3rWard0g (SigmaHQ), DRL 1.1
Published
2019-08-12
Updated
2026-07-31

ATT&CK techniques

Cred Access → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows Security auditing events where a process requests a handle to a registry key whose name ends with '\SAM'. Access to the SAM hive is significant because it can indicate preparation for credential access or other sensitive account-related operations. It relies on Security log Event ID 4656 telemetry with Key object details, including ObjectType and ObjectName suffix matching for '\SAM'.

Related detections9 linkedT1012 — drag to rearrange
Registry Query for WDigest
Suspicious Installed Software Enumeration via Registry Uninstall Key Query
Suspicious Registry Query for Stored Credentials (via process_creation)
Windows WMI StdRegProv Registry Enumeration via wmic.exe
Windows reg.exe Registry Save/Export of Third-Party Credential Paths
PowerShell Registry Reconnaissance Indicators on Windows via Script Block Logging
Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)
Windows CLI Enumeration of 3rd-Party Credential Registry Keys
Windows reg.exe Credential Enumeration via Registry Query (HKLM/HKCU)
Windows Security Event 4656: SAM Registry Hive Key Handle Requested
Pivot detection · T1012 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.