System Event ID 6006: Event Log service stopped
- Event ID
- 6006
- Channel
- System
- Provider
- EventLog
- Log file
- System.evtx
- Category
- System
- Default logging
- Logged by default
What event 6006 means
Event 6006 is logged by the Event Log service as it shuts down. On a normal shutdown or restart it sits next to 1074 (who asked) and 13 (kernel shutdown), and the next boot begins with 12 and 6005.
If a boot follows without a 6006 before it, the previous session ended abruptly and Windows will log 6008 (unexpected shutdown) and usually 41. The Security log has a parallel record, 1100 (the event logging service has shut down).
The event has no useful data; the timestamp is what counts. A 6006 that is not followed by a shutdown, with the host clearly still running afterwards, indicates that the Event Log service was stopped on purpose.
When it is logged
Always logged to the System log when the Event Log service stops.
Key fields
| Field | What it tells you |
|---|---|
| Data1 | Empty. The event carries no insertion strings; use the record time. |
Common benign sources
- Every clean shutdown and restart.
What attackers do that produces it
- Stopping the Event Log service with service control commands to blind defenders — look for a 6006 not followed by 13 and 12. (Thread-killing tools that suspend logging leave no 6006.)
Investigation tips
- Confirm the shutdown sequence 1074, 6006, 13; a 6006 without the other two is suspicious.
- Compare with Security 1100 and look for the gap until the next 6005.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1685.001 Disable or Modify Tools: Disable or Modify Windows Event Log | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.