System Event ID 6005: Event Log service started
- Event ID
- 6005
- Channel
- System
- Provider
- EventLog
- Log file
- System.evtx
- Category
- System
- Default logging
- Logged by default
What event 6005 means
Event 6005 is logged by the Event Log service as soon as it starts. Since the service starts automatically early in boot and is not normally restarted, 6005 is effectively a boot marker, paired with 6006 (service stopped) at shutdown. It is often used for uptime reports together with 6013.
It carries no useful data: the timestamp is the evidence. Its position relative to kernel event 12 is also informative — 12 comes first (kernel start), 6005 follows seconds later once logging is up. Records between the two are generated from boot-time buffers.
A 6005 that is not near a 12 means the Event Log service itself was restarted while the system stayed up, which is unusual and worth explaining.
When it is logged
Always logged to the System log when the Event Log service starts.
Key fields
| Field | What it tells you |
|---|---|
| Data1 | Empty. The event carries no insertion strings; use the record time. |
Common benign sources
- Every system boot.
What attackers do that produces it
- A 6005 in the middle of a session, after a 6006 or a gap, can reveal an attacker who stopped and restarted the Event Log service to suspend logging.
Investigation tips
- Pair each 6005 with a 12 from Kernel-General; a lone 6005 means a service restart, not a boot.
- Check the previous records for 6006 or for a gap in time and record IDs.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1685.001 Disable or Modify Tools: Disable or Modify Windows Event Log | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.