Skip to content
Security

Event ID 5377: Credential Manager restore

Credential Manager credentials were restored from a backupSecurity event 5377 records Credential Manager credentials restored from a backup file into a user's vault. Rare; confirm each one.
5377
Event ID
5377
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Logged by default

What event 5377 means

Event 5377 is written when a user restores Credential Manager credentials from a backup file, usually through Control Panel > Credential Manager > Restore Credentials. The saved credentials from the file become available to that user's session.

Like the backup event 5376, it is rarely seen in normal use and deserves a check each time. A restore on an unexpected host means stored credentials for shares, RDP targets or applications were brought onto that machine.

The record names only the account and logon session, not the backup file or the program used.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled in the default audit policy.

Generated on workstations, member servers and domain controllers. The event does not include the backup file path or the process that performed the operation.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that restored its Credential Manager credentials.
SubjectDomainNameDomain or computer name of that account.
SubjectUserSidSID of that account.
SubjectLogonIdLogon session that performed the operation. Pivot to 4624 (LogonType) and 4688 (processes run in the same session).

Common benign sources

  • A user moving saved credentials to a replacement computer after a 5376 on the old one.
  • Profile restoration during a device rebuild.

What attackers do that produces it

  • Importing another user's exported credentials into an account the attacker controls.

Investigation tips

  • Find the matching 5376 (same account, earlier, possibly on another host) to understand where the credentials came from.
  • Pivot on SubjectLogonId to the 4624 and 4688 of the session to see how the user logged on and what ran.

MITRE ATT&CK techniques

TechniqueTactics
T1555.004 Credentials from Password Stores: Windows Credential ManagerCredential Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading