Skip to content
System

System Event ID 7000: Service failed to start

The service failed to start due to the following errorSystem event 7000 is logged when a service fails to start, with the error. Often follows a malicious 7045 whose payload is not a real service binary.
7000
Event ID
7000
Channel
System
Provider
Service Control Manager
Log file
System.evtx
Category
Services
Default logging
Logged by default

What event 7000 means

Event 7000 is written by the Service Control Manager when it cannot start a service. param1 is the service display name and param2 the error text, such as "The system cannot find the file specified", "Access is denied" or "The service did not respond to the start or control request in a timely fashion".

Most 7000 records are operational: uninstalled software leaving a service behind, a driver that no longer matches the hardware, or a service account with an expired password. In an investigation, 7000 matters when it follows a 7045 by seconds. Many offensive tools register a service whose ImagePath is a plain command (cmd.exe /c ...) or a non-service executable: the command runs, but the process never reports to the SCM, so the start is recorded as a failure (7009 timeout, then 7000) even though the payload executed.

So a failed start is not proof that nothing happened. Check process creation for what the service command actually launched.

When it is logged

Audit policy / configuration

Always logged to the System log.

Key fields

FieldWhat it tells you
param1Display name of the service that failed to start.
param2Error text returned by the SCM, e.g. "The system cannot find the file specified" (binary deleted) or "The service did not respond to the start or control request in a timely fashion".

Common benign sources

  • Leftover services of uninstalled software pointing to missing files.
  • Services with a changed or expired service account password (logon failure errors).
  • Drivers for absent hardware.

What attackers do that produces it

  • Service-based remote execution (Impacket smbexec.py, similar tools) where the service runs a command instead of a service binary: 7045, then 7009 and 7000 within about 30 seconds.
  • A persistence service whose payload was quarantined by antivirus, failing at every boot.

Investigation tips

  • Look for a 7045 for the same service just before; the pair is a strong lateral movement indicator.
  • Read the ImagePath from the 7045 or the registry and search process creation (4688, Sysmon 1) at the same time for its child processes.
  • Repeated 7000 at each boot for an unknown service can reveal broken or quarantined persistence.

MITRE ATT&CK techniques

TechniqueTactics
T1569.002 System Services: Service ExecutionExecution
T1543.003 Create or Modify System Process: Windows ServicePersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading