Skip to content
System

System Event ID 7009: Service start timeout

A timeout was reached while waiting for the service to connectSystem event 7009: a service did not report to the SCM within the timeout (30 s by default). Common with command-based malicious services.
7009
Event ID
7009
Channel
System
Provider
Service Control Manager
Log file
System.evtx
Category
Services
Default logging
Logged by default

What event 7009 means

Event 7009 is written when the Service Control Manager starts a service process but the process never connects back to it within the start timeout. param1 is the timeout in milliseconds (30000 by default) and param2 the service name. It is almost always followed by 7000 for the same service.

Legitimately, this happens with slow or hung services, often at boot on overloaded systems. From a DFIR perspective it is interesting because a service whose ImagePath is not a real service binary — cmd.exe /c <command>, powershell.exe ..., an ordinary executable — behaves exactly this way: Windows launches the command, the command runs, and the SCM gives up waiting. Several remote execution tools produce this sequence on the target: 7045, then 7009 about 30 seconds later, then 7000.

Treat 7009 after a fresh 7045 as evidence of execution attempt, not of failure.

When it is logged

Audit policy / configuration

Always logged to the System log.

The timeout can be changed with the ServicesPipeTimeout registry value, so param1 may differ from 30000 on tuned systems.

Key fields

FieldWhat it tells you
param1Timeout that was reached, in milliseconds (30000 by default).
param2Name of the service that did not connect.

Common benign sources

  • Slow services at boot on busy or under-provisioned servers and VMs.
  • Hung services after failed updates.

What attackers do that produces it

  • Remote command execution through a temporary service whose binary path is a command line, producing 7045, 7009 and 7000 in quick succession.

Investigation tips

  • Check for a 7045 for the same service in the preceding minute and read its ImagePath.
  • Search process creation around the 7045 time for children of services.exe (cmd.exe, powershell.exe).
  • Identify the source host via 4624 type 3 logons and 5145 svcctl pipe access just before.

MITRE ATT&CK techniques

TechniqueTactics
T1569.002 System Services: Service ExecutionExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading