Event ID 5376: Credential Manager backup
- Event ID
- 5376
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Logged by default
What event 5376 means
Event 5376 is written when a user backs up their Credential Manager credentials — the saved Windows and web credentials used for network shares, RDP, and applications. The usual route is Control Panel > Credential Manager > Back up Credentials, which writes the vault to a protected backup file.
Few users ever do this, which is why Microsoft recommends reviewing every occurrence. A backup moves stored credentials into a portable file, so an unexpected 5376 on a server or in an administrator's session is worth explaining.
The record is minimal: it names only the account and logon session. Surrounding process activity (4688, Sysmon 1) is needed to tell which program was running at the time.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled in the default audit policy.
Generated on workstations, member servers and domain controllers. The event does not include the backup file path or the process that performed the operation.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that backed up its Credential Manager credentials. |
| SubjectDomainName | Domain or computer name of that account. |
| SubjectUserSid | SID of that account. |
| SubjectLogonId | Logon session that performed the operation. Pivot to 4624 (LogonType) and 4688 (processes run in the same session). |
Common benign sources
- A user migrating saved credentials to a new computer.
- Help desk procedures backing up a profile's credentials before a rebuild.
What attackers do that produces it
- Exporting a user's saved credentials from their session as a step toward stealing stored passwords.
- Backup activity in a session that was just created remotely (RDP or other remote logon).
Investigation tips
- Verify with the user whether the backup was intentional.
- Pivot on SubjectLogonId to the 4624 to see whether the session was local or remote, and to 4688 for the processes run in that session around the same time.
- Look for a later 5377 on another host with the same account, which shows where the credentials were restored.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1555.004 Credentials from Password Stores: Windows Credential Manager | Credential Access |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.