SAM/SYSTEM Registry Hive Dump
Saving the SAM, SYSTEM and SECURITY registry hives to disk to extract local account password hashes offline using the boot key stored in SYSTEM.
Local account password hashes on a Windows host live in the SAM (Security Account Manager) registry hive, encrypted with a machine-specific boot key derived from values scattered across the SYSTEM hive. Both hives are locked while Windows is running, but the built-in registry tools can still export a consistent snapshot of a live hive to a file, which is all an attacker needs.
How it works
The registry API used to back up a hive to disk is available to any sufficiently privileged process, no special tooling required:
reg.exe save HKLM\SAM C:\Windows\Temp\sam.hiv
reg.exe save HKLM\SYSTEM C:\Windows\Temp\system.hivSECURITY is sometimes saved too, since it holds cached domain credentials
and LSA secrets. The three files are then moved off-host and parsed offline:
the boot key is reconstructed from SYSTEM, used to decrypt SAM's per-user
F/V values, and the result is a standard NTLM hash per local account —
identical in format to a hash recovered from LSASS memory.
Detection & analysis
- Static — A dropped batch/PowerShell script invoking
reg.exe saveagainstHKLM\SAM,HKLM\SYSTEMorHKLM\SECURITY, or a compiled tool linking the equivalentRegSaveKeyWAPI, is unambiguous — there is no legitimate reason for arbitrary software to do this. - Dynamic — Sysmon Event ID 1 (ProcessCreate) for
reg.exewithsavein its command line and one of the three hive names is a high-confidence, low-noise detection. File-creation alerts for new.hivfiles under a user-writable directory are a good secondary signal. - Alternative collection vector — Rather than
reg.exe save, an attacker can take a Volume Shadow Copy ofC:\and read the hive files directly from the shadow's frozen filesystem, bypassing the "hive is in use" lock without invokingreg.exeat all. Watch for shadow-copy creation (vssadmin,wmic shadowcopy) outside of legitimate backup software. - Tools — Sysmon (EID 1, EID 11), Impacket's
secretsdump.py(both for understanding the offline-parsing side and for authorized testing), Volatility 3 for post-incident hive extraction from a memory or disk image.