Skip to content

SAM/SYSTEM Registry Hive Dump

Saving the SAM, SYSTEM and SECURITY registry hives to disk to extract local account password hashes offline using the boot key stored in SYSTEM.

Local account password hashes on a Windows host live in the SAM (Security Account Manager) registry hive, encrypted with a machine-specific boot key derived from values scattered across the SYSTEM hive. Both hives are locked while Windows is running, but the built-in registry tools can still export a consistent snapshot of a live hive to a file, which is all an attacker needs.

How it works

The registry API used to back up a hive to disk is available to any sufficiently privileged process, no special tooling required:

text
reg.exe save HKLM\SAM   C:\Windows\Temp\sam.hiv
reg.exe save HKLM\SYSTEM C:\Windows\Temp\system.hiv

SECURITY is sometimes saved too, since it holds cached domain credentials and LSA secrets. The three files are then moved off-host and parsed offline: the boot key is reconstructed from SYSTEM, used to decrypt SAM's per-user F/V values, and the result is a standard NTLM hash per local account — identical in format to a hash recovered from LSASS memory.

Detection & analysis

  • Static — A dropped batch/PowerShell script invoking reg.exe save against HKLM\SAM, HKLM\SYSTEM or HKLM\SECURITY, or a compiled tool linking the equivalent RegSaveKeyW API, is unambiguous — there is no legitimate reason for arbitrary software to do this.
  • Dynamic — Sysmon Event ID 1 (ProcessCreate) for reg.exe with save in its command line and one of the three hive names is a high-confidence, low-noise detection. File-creation alerts for new .hiv files under a user-writable directory are a good secondary signal.
  • Alternative collection vector — Rather than reg.exe save, an attacker can take a Volume Shadow Copy of C:\ and read the hive files directly from the shadow's frozen filesystem, bypassing the "hive is in use" lock without invoking reg.exe at all. Watch for shadow-copy creation (vssadmin, wmic shadowcopy) outside of legitimate backup software.
  • Tools — Sysmon (EID 1, EID 11), Impacket's secretsdump.py (both for understanding the offline-parsing side and for authorized testing), Volatility 3 for post-incident hive extraction from a memory or disk image.
Votes

Comments(0)