Skip to content
Security

Event ID 4697: Service installed

A service was installed in the systemSecurity event 4697 records a new Windows service with its name, binary path, start type and account. Key for PsExec-style lateral movement and persistence.
4697
Event ID
4697
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Services
Default logging
Needs configuration

What event 4697 means

Event 4697 is written when a service is registered with the Service Control Manager. It records the service name (ServiceName), the command it will run (ServiceFileName), how it starts (ServiceStartType), its type (ServiceType) and the account it runs as (ServiceAccount), together with the account that installed it (Subject*).

It is the Security-log twin of System event 7045, which is logged by the Service Control Manager on every system without any audit policy. 4697 needs the Security System Extension subcategory, but adds the installing account and logon session — useful to tie the install to a specific remote logon.

New services are a favorite for both persistence and remote execution: PsExec, Impacket smbexec/psexec, Cobalt Strike jump psexec and many ransomware operators create a service on the target to run their payload as SYSTEM. Driver installations (kernel services) also show up here.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > System > Audit Security System Extension (Success). Not enabled in the default audit policy.

System event 7045 covers the same installs by default and should be checked when 4697 is not audited.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that installed the service. For remote installs this is the remote admin account; HOST$ means SYSTEM.
SubjectLogonIdLogon session of the installer; pivot to its 4624 (often a type 3 network logon) to find the source.
ServiceNameName of the new service. Random-looking or very short names are a red flag.
ServiceFileNameCommand line the service runs. Look for cmd.exe /c, powershell, paths under \Temp\, ADMIN$ / C:\Windows\ root, or encoded arguments.
ServiceTypeKind of service.
ValueMeaning
0x1Kernel driver.
0x2File system driver.
0x8Recognizer driver.
0x10Win32 service running in its own process.
0x20Win32 service sharing a process (svchost-hosted).
0x110Own-process service allowed to interact with the desktop.
0x120Shared-process service allowed to interact with the desktop.
ServiceStartTypeWhen the service starts.
ValueMeaning
0Boot — driver loaded by the boot loader.
1System — driver started during kernel initialization.
2Automatic — started at boot by the Service Control Manager.
3Manual (demand start).
4Disabled.
ServiceAccountAccount the service runs as, e.g. LocalSystem, NT AUTHORITY\LocalService or a domain account.

Common benign sources

  • Software installs and updates (drivers, agents, browsers' update services).
  • Management and remote support tools that install a temporary service on the target.
  • Windows feature and role installation.

What attackers do that produces it

  • Remote execution via PsExec or Impacket: a new demand-start service with a random or tool-specific name, running a binary from ADMIN$ or a cmd.exe /c / %COMSPEC% command line.
  • Persistence through an automatic-start service pointing to a payload in a user-writable folder.
  • Loading a malicious or vulnerable kernel driver (ServiceType 0x1, start type 0–3) to disable security tools.

Investigation tips

  • Review ServiceFileName first: anything outside Program Files / System32 or containing a shell, script host or encoded blob deserves attention.
  • Pivot on SubjectLogonId to the 4624 on the same host — a type 3 logon seconds before the install reveals the source IP of remote execution.
  • Correlate with System 7045 and 7036 (service started/stopped) to see whether it ran and was removed.
  • Look for 4688 children of services.exe right after the install to see what the service executed.

MITRE ATT&CK techniques

TechniqueTactics
T1543.003 Create or Modify System Process: Windows ServicePersistence, Privilege Escalation
T1569.002 System Services: Service ExecutionExecution
T1021.002 Remote Services: SMB/Windows Admin SharesLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

21 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 16
  • Medium · 4
  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideEvent ID 4697: a service was installed (and why it beats 7045)

Sources and further reading