Windows Security log shows 4648 explicit credentials for local admin “John”, many 5379 Credential Manager reads, and a single 7045 GoogleUpdaterService install — normal or suspicious?

John William Dezell 0 Reputation points
2025-10-01T16:32:17.8133333+00:00
  1. Version/Environment: Windows 11; local admin “John”; mostly Logon Type 5 (service) starts; routine updates.
  2. Problem summary:
    • 4648 (explicit credentials) during boot by SYSTEM/wininit using John’s creds; many 5379 Credential Manager reads at startup; 7045 service install is Google updater.
    • No Type 3/10 logons; pattern appears benign but want Microsoft’s stance and hardening advice. Executive Summary_SIR_09_27_2025
  3. Evidence: Sequence of 4624 Type 5 service logons, 4648 uses of John’s creds by SYSTEM, and 7045 for legitimate Google updater; recommendation to verify tasks and audit policy consistency. Executive Summary_SIR_09_27_2025
  4. What I’ve tried: Mapped events to expected startup behavior; checked for unknown services/tasks (none found in logs). Executive Summary_SIR_09_27_2025
  5. Specific questions:
    1. Is repeated 5379 at boot normal on Windows 11 with Credential Manager (drives/VPN/app secrets), and is there a recommended alert threshold? Executive Summary_SIR_09_27_2025
    2. Best-practice to audit/limit SYSTEM using a user’s creds (4648) at boot — purely scheduled task hygiene? Executive Summary_SIR_09_27_2025
    3. Any Microsoft reference baselines for expected 7045 patterns from first-party/known vendors?
  6. Attachments: “Executive Summary_SIR_09_27_2025.docx”. Executive Summary_SIR_09_27_2025

TL;DR: Need official guidance on interpreting (and alerting on) 4648/5379/7045 patterns that look benign but noisy; want hardening steps to reduce false positives.

Windows for home | Windows 11 | Security and privacy

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.