Event ID 5379
Records instances where Credential Manager credentials were readCredential Manager credentials were read.
Subject:
Security ID: %1
Account Name: %2
Account Domain: %3
Logon ID: %4
Read Operation: %5
This event occurs when a user performs a read operation on stored credentials in Credential Manager.When a user or a service accesses credentials (like Windows credentials, web credentials, domain tokens, or certificates) stored within the Windows Credential Manager vault, this event is triggered.
Some of the insertion strings (TargetName and below) will now show in the event message and are only available in the XML view of the event.
Auditing: Conditional
Volume: LowMediumHighVery High
Low to medium on servers, high to very high on workstations
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"User Account Management" LEFT/RIGHT arrow keys for navigation
Back to List