Windows Security log shows 4648 explicit credentials for local admin “John”, many 5379 Credential Manager reads, and a single 7045 GoogleUpdaterService install — normal or suspicious?
John William Dezell
0
Reputation points
- Version/Environment: Windows 11; local admin “John”; mostly Logon Type 5 (service) starts; routine updates.
- Problem summary:
- 4648 (explicit credentials) during boot by SYSTEM/wininit using John’s creds; many 5379 Credential Manager reads at startup; 7045 service install is Google updater.
- No Type 3/10 logons; pattern appears benign but want Microsoft’s stance and hardening advice. Executive Summary_SIR_09_27_2025
- Evidence: Sequence of 4624 Type 5 service logons, 4648 uses of John’s creds by SYSTEM, and 7045 for legitimate Google updater; recommendation to verify tasks and audit policy consistency. Executive Summary_SIR_09_27_2025
- What I’ve tried: Mapped events to expected startup behavior; checked for unknown services/tasks (none found in logs). Executive Summary_SIR_09_27_2025
- Specific questions:
- Is repeated 5379 at boot normal on Windows 11 with Credential Manager (drives/VPN/app secrets), and is there a recommended alert threshold? Executive Summary_SIR_09_27_2025
- Best-practice to audit/limit SYSTEM using a user’s creds (4648) at boot — purely scheduled task hygiene? Executive Summary_SIR_09_27_2025
- Any Microsoft reference baselines for expected 7045 patterns from first-party/known vendors?
- Attachments: “Executive Summary_SIR_09_27_2025.docx”. Executive Summary_SIR_09_27_2025
TL;DR: Need official guidance on interpreting (and alerting on) 4648/5379/7045 patterns that look benign but noisy; want hardening steps to reduce false positives.
Windows for home | Windows 11 | Security and privacy
Sign in to answer