Skip to content
Sysmon

Sysmon Event ID 4: Service state changed

Sysmon service state changedSysmon event 4 reports the Sysmon service starting or stopping. An unexpected stop outside maintenance can mean someone is blinding endpoint telemetry.
4
Event ID
4
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Log integrity
Default logging
Needs configuration

What event 4 means

Sysmon event 4 is written when the Sysmon service changes state, with State set to Started or Stopped, and the Sysmon binary and schema versions.

Starts appear at every boot and after upgrades. A Stopped record outside a reboot or a planned upgrade deserves attention: attackers who gain admin rights often unload the Sysmon driver or stop the service before doing anything noisy. Note that an attacker who kills the service abruptly may leave no stop record at all, so a gap in Sysmon events is itself a signal.

When it is logged

Audit policy / configuration

Sysmon installed. This event cannot be filtered by the configuration.

Key fields

FieldWhat it tells you
UtcTimeTime of the state change.
StateNew state of the service.
ValueMeaning
StartedThe Sysmon service started (boot, install or upgrade).
StoppedThe Sysmon service stopped.
VersionSysmon binary version. Useful to track upgrades and fleet consistency.
SchemaVersionConfiguration schema version in use.

Common benign sources

  • Service start at every boot.
  • Stop and start around a planned Sysmon upgrade or reinstall.

What attackers do that produces it

  • An administrator-level attacker stopping Sysmon or unloading its driver (fltmc unload) to stop telemetry.
  • Uninstalling Sysmon (sysmon -u) before lateral movement or ransomware deployment.

Investigation tips

  • Check whether a stop lines up with a shutdown (System 1074, 6006) or an upgrade; if not, treat it as tampering.
  • Look at the process and service events just before the stop (Security 4688, System 7036/7040).
  • Hunt for time gaps in Sysmon/Operational without a matching stop record.

MITRE ATT&CK techniques

TechniqueTactics
T1685 Disable or Modify ToolsDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading