Event ID 4697: Service installed
- Event ID
- 4697
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Services
- Default logging
- Needs configuration
What event 4697 means
Event 4697 is written when a service is registered with the Service Control Manager. It records the service name (ServiceName), the command it will run (ServiceFileName), how it starts (ServiceStartType), its type (ServiceType) and the account it runs as (ServiceAccount), together with the account that installed it (Subject*).
It is the Security-log twin of System event 7045, which is logged by the Service Control Manager on every system without any audit policy. 4697 needs the Security System Extension subcategory, but adds the installing account and logon session — useful to tie the install to a specific remote logon.
New services are a favorite for both persistence and remote execution: PsExec, Impacket smbexec/psexec, Cobalt Strike jump psexec and many ransomware operators create a service on the target to run their payload as SYSTEM. Driver installations (kernel services) also show up here.
When it is logged
Advanced Audit Policy Configuration > System > Audit Security System Extension (Success). Not enabled in the default audit policy.
System event 7045 covers the same installs by default and should be checked when 4697 is not audited.
Key fields
| Field | What it tells you | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SubjectUserName | Account that installed the service. For remote installs this is the remote admin account; HOST$ means SYSTEM. | ||||||||||||||||
| SubjectLogonId | Logon session of the installer; pivot to its 4624 (often a type 3 network logon) to find the source. | ||||||||||||||||
| ServiceName | Name of the new service. Random-looking or very short names are a red flag. | ||||||||||||||||
| ServiceFileName | Command line the service runs. Look for cmd.exe /c, powershell, paths under \Temp\, ADMIN$ / C:\Windows\ root, or encoded arguments. | ||||||||||||||||
| ServiceType | Kind of service.
| ||||||||||||||||
| ServiceStartType | When the service starts.
| ||||||||||||||||
| ServiceAccount | Account the service runs as, e.g. LocalSystem, NT AUTHORITY\LocalService or a domain account. |
Common benign sources
- Software installs and updates (drivers, agents, browsers' update services).
- Management and remote support tools that install a temporary service on the target.
- Windows feature and role installation.
What attackers do that produces it
- Remote execution via PsExec or Impacket: a new demand-start service with a random or tool-specific name, running a binary from
ADMIN$or acmd.exe /c/%COMSPEC%command line. - Persistence through an automatic-start service pointing to a payload in a user-writable folder.
- Loading a malicious or vulnerable kernel driver (ServiceType
0x1, start type 0–3) to disable security tools.
Investigation tips
- Review ServiceFileName first: anything outside
Program Files/System32or containing a shell, script host or encoded blob deserves attention. - Pivot on SubjectLogonId to the 4624 on the same host — a type 3 logon seconds before the install reveals the source IP of remote execution.
- Correlate with System 7045 and 7036 (service started/stopped) to see whether it ran and was removed.
- Look for 4688 children of
services.exeright after the install to see what the service executed.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
21 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 16
- Medium · 4
- Low · 1
- HighCobaltStrike Service Installations - SecurityRule by Florian Roth (Nextron Systems), Wojciech Lesicki, SigmaHQ, DRL 1.1
- HighCredential Dumping Tools Service Execution - SecurityRule by Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, SigmaHQ, DRL 1.1
- HighHybridConnectionManager Service InstallationRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation CLIP+ Launcher - SecurityRule by Jonathan Cheong, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Obfuscated IEX Invocation - SecurityRule by Daniel Bohannon (@Mandiant/@FireEye), oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation STDIN+ Launcher - SecurityRule by Jonathan Cheong, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation VAR+ Launcher - SecurityRule by Jonathan Cheong, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - SecurityRule by Timur Zinniatullin, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Via Stdin - SecurityRule by Nikita Nazarov, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Via Use Clip - SecurityRule by Nikita Nazarov, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Via Use MSHTA - SecurityRule by Nikita Nazarov, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Via Use Rundll32 - SecurityRule by Nikita Nazarov, oscd.community, SigmaHQ, DRL 1.1
- HighMetasploit Or Impacket Service Installation Via SMB PsExecRule by Bartlomiej Czyz, Relativity, SigmaHQ, DRL 1.1
- HighMeterpreter or Cobalt Strike Getsystem Service Installation - SecurityRule by Teymur Kheirkhabarov, Ecco, Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighPowerShell Scripts Installed as Services - SecurityRule by oscd.community, Natalia Shornikova, SigmaHQ, DRL 1.1
- HighService Installed By Unusual Client - SecurityRule by Tim Rauch (Nextron Systems), Elastic (idea), SigmaHQ, DRL 1.1
- MediumInvoke-Obfuscation COMPRESS OBFUSCATION - SecurityRule by Timur Zinniatullin, oscd.community, SigmaHQ, DRL 1.1
- MediumInvoke-Obfuscation RUNDLL LAUNCHER - SecurityRule by Timur Zinniatullin, oscd.community, SigmaHQ, DRL 1.1
- MediumRemote Access Tool Services Have Been Installed - SecurityRule by Connor Martin, Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumWindows Pcap DriversRule by Cian Heasley, SigmaHQ, DRL 1.1
- LowTap Driver Installation - SecurityRule by Daniil Yugoslavskiy, Ian Davis, oscd.community, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.