Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SAMRi10 is a PowerShell script that Microsoft Advanced Threat Analytics researchers Itai Grady and Tal Be’ery were reported to have introduced in 2016 to restrict remote queries of Windows Security Accounts Manager (SAM) data. It was described for Windows 10 and Windows Server 2016, but those historical platform details do not confirm that the script is available, maintained, or compatible with current Windows versions.

What SAMRi10 was designed to do

Remote SAMR queries can expose account and group information. An attacker who has compromised a computer inside a domain may use that information to map users and find accounts or systems worth targeting. SAMRi10 was designed to limit this remote enumeration path, not to remove malware or block every form of reconnaissance.

BleepingComputer’s December 1, 2016 report described SAMRi10 as a PowerShell script for system administrators to run on networked computers. The report attributed its development to Microsoft Advanced Threat Analytics researchers Itai Grady and Tal Be’ery.

How the script was reported to work

The report says SAMRi10 changes the HKLM/System/CurrentControlSet/Control/Lsa/RestrictRemoteSAM registry setting to restrict remote access to SAM databases. It also describes allowing administrators to make remote queries and an option to create a “Remote SAM Users” group for trusted users who need that access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

BleepingComputer reported that the script had been tested against queries from PowerSploit and BloodHound. That is a claim in the 2016 report, not a current compatibility or effectiveness test.

Historical platform and availability limits

The 2016 coverage specified Windows 10 and Windows Server 2016 and said the script should be run with administrative privileges. Treat those as the article’s stated scope at the time, not as confirmation that SAMRi10 works on later Windows releases.

The report linked to a package on TechNet Gallery, but that package page could not be retrieved for this review. Current download availability, maintenance, licensing, source-code integrity, and compatibility are therefore unverified. Do not assume that an old copy found elsewhere is authentic or safe to run.

SAMRi10 versus NetCease

Both scripts were covered in 2016 as ways to limit forms of network enumeration, but they address different methods and should not be treated as interchangeable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
HP 2020 15.6" Touchscreen Laptop Computer/ 10th Gen Intel Quard-Core i5 1035G1 up to 3.6GHz/ 12GB DDR4 RAM/ 256GB PCIe SSD/ 802.11ac WiFi/Bluetooth 4.2/ USB 3.1 Type-C/HDMI/Silver/Windows 10 Home
  • 10th Generation Intel Core i5-1035G1 processor
  • 12GB system memory for full-power multitasking
  • 256GB Solid State Drive
  • 15.6" Micro-edge touchscreen display
Tool Reported target Reported mechanism Evidence limit
SAMRi10 Remote SAMR queries of SAM data Edits the RestrictRemoteSAM registry setting Historical 2016 coverage; current package and support unverified. BleepingComputer
NetCease NetSessionEnum session enumeration Changes access permissions Historical reporting describes a separate tool and mechanism. SecurityWeek and Help Net Security

SecurityWeek’s October 14, 2016 report describes NetCease as hardening access to NetSessionEnum by removing execute permission for Authenticated Users and adding permissions for certain interactive, service, and batch logon contexts. That is distinct from SAMRi10’s reported restriction of remote SAM database access.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

It is not Microsoft’s malware removal tool

SAMRi10 is also unrelated to Microsoft’s Windows Malicious Software Removal Tool (MSRT). Microsoft describes MSRT as a post-infection utility for removing specific prevalent malware and says it does not replace antivirus software. Its function is different from SAMRi10’s reported account-enumeration hardening. See Microsoft’s MSRT documentation.

Rank #4
Dell Latitude 7480 Laptop 14 - Intel Core i7 6th Gen - i7-6600U - 3.4Ghz - 256GB SSD - 16GB RAM - 1920x1080 FHD - Windows 10 Pro (Renewed)
  • Latitude 7480 Laptop 14"
  • Intel Core i7 6th Gen i7-6600U -Core Processor 2.6GHz (3.4GHz With Turbo Boost)
  • 256 GB SSD Hard Drive & 16GB Memory
  • 1920x1080 FHD resolution Non-Touch with Webcam and an integrated graphics chip
  • Wireless Wifi & Bluetooth

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.