Keywords,Date and Time,Source,Event ID,Task Category
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Read Credential
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential Manager credentials were read.
Subject:
Security ID: JAKE-PC\Admin
Account Name: Admin
Account Domain: JAKE-PC
Logon ID: 0xEE27E8
Read Operation: Enumerate Credentials
This event occurs when a user performs a read operation on stored credentials in Credential Manager."
Audit Success,8/24/2021 12:29:56 PM,Microsoft-Windows-Security-Auditing,5379,User Account Management,"Credential