Sysmon Event ID 4: Service state changed
- Event ID
- 4
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Log integrity
- Default logging
- Needs configuration
What event 4 means
Sysmon event 4 is written when the Sysmon service changes state, with State set to Started or Stopped, and the Sysmon binary and schema versions.
Starts appear at every boot and after upgrades. A Stopped record outside a reboot or a planned upgrade deserves attention: attackers who gain admin rights often unload the Sysmon driver or stop the service before doing anything noisy. Note that an attacker who kills the service abruptly may leave no stop record at all, so a gap in Sysmon events is itself a signal.
When it is logged
Sysmon installed. This event cannot be filtered by the configuration.
Key fields
| Field | What it tells you | ||||||
|---|---|---|---|---|---|---|---|
| UtcTime | Time of the state change. | ||||||
| State | New state of the service.
| ||||||
| Version | Sysmon binary version. Useful to track upgrades and fleet consistency. | ||||||
| SchemaVersion | Configuration schema version in use. |
Common benign sources
- Service start at every boot.
- Stop and start around a planned Sysmon upgrade or reinstall.
What attackers do that produces it
- An administrator-level attacker stopping Sysmon or unloading its driver (
fltmc unload) to stop telemetry. - Uninstalling Sysmon (
sysmon -u) before lateral movement or ransomware deployment.
Investigation tips
- Check whether a stop lines up with a shutdown (System 1074, 6006) or an upgrade; if not, treat it as tampering.
- Look at the process and service events just before the stop (Security 4688, System 7036/7040).
- Hunt for time gaps in Sysmon/Operational without a matching stop record.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1685 Disable or Modify Tools | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighSysmon Configuration ModificationRule by frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.