name: Credential Dumping sam test detections: - name: Attempted Credential Dump From Registry via Reg exe pass_condition: '| stats count | where count > 0' description: Test credential dumping detections target: attack-range-windows-domain-controller simulation_technique: 'T1003.002'