Burst of 5379 Credential Manager reads at 01:15, concurrent SYSTEM Logon Type 5 + 4672 privileges, and taskhostw.exe 4798 on Administrator — compromise indicators?
John William Dezell
0
Reputation points
- Version/Environment: Windows 11; local admin “John”; interactive logon ~01:04; suspicious activity ~01:15.
- Problem summary:
- Unusual cluster: many 5379 reads (WindowsLive/MicrosoftAccount/Adobe entries), new SYSTEM logon (4624 Type 5) after boot, 4672 special privileges, and taskhostw.exe enumerating Administrator groups — suspect scheduled task elevation & credential dump. Windows Security Log Compromise…
- Evidence: Timeline, event text, and remediation recommendations (isolate, review tasks/services, reset creds). Windows Security Log Compromise…
- What I’ve tried: Local triage; mapped events; prepared containment steps and long-term hardening. Windows Security Log Compromise…
- Specific questions:
- Does Microsoft consider this exact trio (5379 burst + 4624-5 + 4672 + 4798 on Administrator via taskhostw.exe) a high-confidence IOC set, and are there official detection rules? Windows Security Log Compromise…
- Best Microsoft-supported method to enumerate tasks/services created/ran at that second, if 4698/4697 aren’t present (e.g., audit policy, PowerShell history, operational logs)? Windows Security Log Compromise…
- Recommended procedure to invalidate tokens for Microsoft Account sign-in on the device after a 5379 success for that target? Windows Security Log Compromise…
- Attachments: “Windows Security Log Compromise Analysis Report.pdf”. Windows Security Log Compromise…
TL;DR: Requesting Microsoft confirmation that this pattern indicates credential dumping + SYSTEM elevation, and for precise forensics/detection steps. Windows Security Log Compromise…
Windows for home | Windows 11 | Security and privacy
Sign in to answer