Burst of 5379 Credential Manager reads at 01:15, concurrent SYSTEM Logon Type 5 + 4672 privileges, and taskhostw.exe 4798 on Administrator — compromise indicators?

John William Dezell 0 Reputation points
2025-10-01T16:43:23.0166667+00:00
  1. Version/Environment: Windows 11; local admin “John”; interactive logon ~01:04; suspicious activity ~01:15.
  2. Problem summary:
    • Unusual cluster: many 5379 reads (WindowsLive/MicrosoftAccount/Adobe entries), new SYSTEM logon (4624 Type 5) after boot, 4672 special privileges, and taskhostw.exe enumerating Administrator groups — suspect scheduled task elevation & credential dump. Windows Security Log Compromise…
  3. Evidence: Timeline, event text, and remediation recommendations (isolate, review tasks/services, reset creds). Windows Security Log Compromise…
  4. What I’ve tried: Local triage; mapped events; prepared containment steps and long-term hardening. Windows Security Log Compromise…
  5. Specific questions:
    1. Does Microsoft consider this exact trio (5379 burst + 4624-5 + 4672 + 4798 on Administrator via taskhostw.exe) a high-confidence IOC set, and are there official detection rules? Windows Security Log Compromise…
    2. Best Microsoft-supported method to enumerate tasks/services created/ran at that second, if 4698/4697 aren’t present (e.g., audit policy, PowerShell history, operational logs)? Windows Security Log Compromise…
    3. Recommended procedure to invalidate tokens for Microsoft Account sign-in on the device after a 5379 success for that target? Windows Security Log Compromise…
  6. Attachments: “Windows Security Log Compromise Analysis Report.pdf”. Windows Security Log Compromise…

TL;DR: Requesting Microsoft confirmation that this pattern indicates credential dumping + SYSTEM elevation, and for precise forensics/detection steps. Windows Security Log Compromise…

Windows for home | Windows 11 | Security and privacy

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.