Event ID 5377: Credential Manager restore
- Event ID
- 5377
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Logged by default
What event 5377 means
Event 5377 is written when a user restores Credential Manager credentials from a backup file, usually through Control Panel > Credential Manager > Restore Credentials. The saved credentials from the file become available to that user's session.
Like the backup event 5376, it is rarely seen in normal use and deserves a check each time. A restore on an unexpected host means stored credentials for shares, RDP targets or applications were brought onto that machine.
The record names only the account and logon session, not the backup file or the program used.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled in the default audit policy.
Generated on workstations, member servers and domain controllers. The event does not include the backup file path or the process that performed the operation.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that restored its Credential Manager credentials. |
| SubjectDomainName | Domain or computer name of that account. |
| SubjectUserSid | SID of that account. |
| SubjectLogonId | Logon session that performed the operation. Pivot to 4624 (LogonType) and 4688 (processes run in the same session). |
Common benign sources
- A user moving saved credentials to a replacement computer after a 5376 on the old one.
- Profile restoration during a device rebuild.
What attackers do that produces it
- Importing another user's exported credentials into an account the attacker controls.
Investigation tips
- Find the matching 5376 (same account, earlier, possibly on another host) to understand where the credentials came from.
- Pivot on SubjectLogonId to the 4624 and 4688 of the session to see how the user logged on and what ran.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1555.004 Credentials from Password Stores: Windows Credential Manager | Credential Access |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.