Windows Security Log Event ID 5381
Operating Systems |
Windows Server 2019 and 2022
|
Category • Subcategory | System • Other System Events |
Type
|
Success
|
Corresponding events
in Windows
2003 and before |
|
5381: Vault credentials were read
On this page
This event is new in Server 2019. This event occurs when a user enumerates stored vault credentials.
Free Security Log Resources by Randy
Subject:
The user and logon session that performed the action.
- Security ID: The SID of the account.
- Account Name: The account logon name.
- Account Domain: The domain or - in the case of local accounts - computer name.
- Logon ID is a semi-unique (unique between reboots) number that identifies the logon session. Logon ID allows you to correlate backwards to the logon event (4624) as well as with other events logged during the same logon session.
Supercharger Enterprise