System32
Sysmon
Events
Compliance
Validator
TLS/SSL
GeoIP
Tools
Windows Security Events
Audit Category
Account Management
(1)
Operating Systems
Windows 11
(1)
Windows 2019
(1)
Windows 2022
(1)
Windows 2025
(1)
Tags
Auditing
Conditional
(1)
Volume
High
(1)
Low
(1)
Medium
(1)
Very high
(1)
Audit Subcategory
User Account Management
(1)
AppLocker
All AppLocker events
EventSentry
All EventSentry events
Security
All Windows Security events
Sysmon
All Sysmon events
ID
Event Description
5379
Records instances where Credential Manager credentials were read