Skip to content
System

System Event ID 6006: Event Log service stopped

The Event log service was stoppedSystem event 6006 is written when the Event Log service stops, normally at clean shutdown. Missing before a boot means a crash.
6006
Event ID
6006
Channel
System
Provider
EventLog
Log file
System.evtx
Category
System
Default logging
Logged by default

What event 6006 means

Event 6006 is logged by the Event Log service as it shuts down. On a normal shutdown or restart it sits next to 1074 (who asked) and 13 (kernel shutdown), and the next boot begins with 12 and 6005.

If a boot follows without a 6006 before it, the previous session ended abruptly and Windows will log 6008 (unexpected shutdown) and usually 41. The Security log has a parallel record, 1100 (the event logging service has shut down).

The event has no useful data; the timestamp is what counts. A 6006 that is not followed by a shutdown, with the host clearly still running afterwards, indicates that the Event Log service was stopped on purpose.

When it is logged

Audit policy / configuration

Always logged to the System log when the Event Log service stops.

Key fields

FieldWhat it tells you
Data1Empty. The event carries no insertion strings; use the record time.

Common benign sources

  • Every clean shutdown and restart.

What attackers do that produces it

  • Stopping the Event Log service with service control commands to blind defenders — look for a 6006 not followed by 13 and 12. (Thread-killing tools that suspend logging leave no 6006.)

Investigation tips

  • Confirm the shutdown sequence 1074, 6006, 13; a 6006 without the other two is suspicious.
  • Compare with Security 1100 and look for the gap until the next 6005.

MITRE ATT&CK techniques

TechniqueTactics
T1685.001 Disable or Modify Tools: Disable or Modify Windows Event LogDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading