Event ID 5377 — Credential Manager credentials were restored from a backup.
Description
Credential Manager credentials were restored from a backup.
Message #
Fields #
| Name | Description |
|---|---|
SubjectUserSid SID | [Subject] Security ID |
SubjectUserName UnicodeString | [Subject] Account Name |
SubjectDomainName UnicodeString | [Subject] Account Domain |
SubjectLogonId HexInt64 | [Subject] Logon ID |
BackupFileName UnicodeString | [Subject] BackupFileName |
ProcessCreationTime FILETIME | — |
ClientProcessId UInt32 | — |
Community Notes #
Credential Manager credentials were restored from a backup, may indicate import of stolen vaults from another host.
References #
- Microsoft Learn Audit Policy https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-user-account-management