Skip to content
System

System Event ID 6005: Event Log service started

The Event log service was startedSystem event 6005 is written when the Event Log service starts, which in practice means at every boot. A simple, reliable startup marker next to event 12.
6005
Event ID
6005
Channel
System
Provider
EventLog
Log file
System.evtx
Category
System
Default logging
Logged by default

What event 6005 means

Event 6005 is logged by the Event Log service as soon as it starts. Since the service starts automatically early in boot and is not normally restarted, 6005 is effectively a boot marker, paired with 6006 (service stopped) at shutdown. It is often used for uptime reports together with 6013.

It carries no useful data: the timestamp is the evidence. Its position relative to kernel event 12 is also informative — 12 comes first (kernel start), 6005 follows seconds later once logging is up. Records between the two are generated from boot-time buffers.

A 6005 that is not near a 12 means the Event Log service itself was restarted while the system stayed up, which is unusual and worth explaining.

When it is logged

Audit policy / configuration

Always logged to the System log when the Event Log service starts.

Key fields

FieldWhat it tells you
Data1Empty. The event carries no insertion strings; use the record time.

Common benign sources

  • Every system boot.

What attackers do that produces it

  • A 6005 in the middle of a session, after a 6006 or a gap, can reveal an attacker who stopped and restarted the Event Log service to suspend logging.

Investigation tips

  • Pair each 6005 with a 12 from Kernel-General; a lone 6005 means a service restart, not a boot.
  • Check the previous records for 6006 or for a gap in time and record IDs.

MITRE ATT&CK techniques

TechniqueTactics
T1685.001 Disable or Modify Tools: Disable or Modify Windows Event LogDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading