Skip to content
Security

Event ID 5376: Credential Manager backup

Credential Manager credentials were backed upSecurity event 5376 records a backup of a user's Credential Manager vault. Rarely used by real users, so worth checking every time.
5376
Event ID
5376
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Logged by default

What event 5376 means

Event 5376 is written when a user backs up their Credential Manager credentials — the saved Windows and web credentials used for network shares, RDP, and applications. The usual route is Control Panel > Credential Manager > Back up Credentials, which writes the vault to a protected backup file.

Few users ever do this, which is why Microsoft recommends reviewing every occurrence. A backup moves stored credentials into a portable file, so an unexpected 5376 on a server or in an administrator's session is worth explaining.

The record is minimal: it names only the account and logon session. Surrounding process activity (4688, Sysmon 1) is needed to tell which program was running at the time.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled in the default audit policy.

Generated on workstations, member servers and domain controllers. The event does not include the backup file path or the process that performed the operation.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that backed up its Credential Manager credentials.
SubjectDomainNameDomain or computer name of that account.
SubjectUserSidSID of that account.
SubjectLogonIdLogon session that performed the operation. Pivot to 4624 (LogonType) and 4688 (processes run in the same session).

Common benign sources

  • A user migrating saved credentials to a new computer.
  • Help desk procedures backing up a profile's credentials before a rebuild.

What attackers do that produces it

  • Exporting a user's saved credentials from their session as a step toward stealing stored passwords.
  • Backup activity in a session that was just created remotely (RDP or other remote logon).

Investigation tips

  • Verify with the user whether the backup was intentional.
  • Pivot on SubjectLogonId to the 4624 to see whether the session was local or remote, and to 4688 for the processes run in that session around the same time.
  • Look for a later 5377 on another host with the same account, which shows where the credentials were restored.

MITRE ATT&CK techniques

TechniqueTactics
T1555.004 Credentials from Password Stores: Windows Credential ManagerCredential Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading