System Event ID 7009: Service start timeout
- Event ID
- 7009
- Channel
- System
- Provider
- Service Control Manager
- Log file
- System.evtx
- Category
- Services
- Default logging
- Logged by default
What event 7009 means
Event 7009 is written when the Service Control Manager starts a service process but the process never connects back to it within the start timeout. param1 is the timeout in milliseconds (30000 by default) and param2 the service name. It is almost always followed by 7000 for the same service.
Legitimately, this happens with slow or hung services, often at boot on overloaded systems. From a DFIR perspective it is interesting because a service whose ImagePath is not a real service binary — cmd.exe /c <command>, powershell.exe ..., an ordinary executable — behaves exactly this way: Windows launches the command, the command runs, and the SCM gives up waiting. Several remote execution tools produce this sequence on the target: 7045, then 7009 about 30 seconds later, then 7000.
Treat 7009 after a fresh 7045 as evidence of execution attempt, not of failure.
When it is logged
Always logged to the System log.
The timeout can be changed with the ServicesPipeTimeout registry value, so param1 may differ from 30000 on tuned systems.
Key fields
| Field | What it tells you |
|---|---|
| param1 | Timeout that was reached, in milliseconds (30000 by default). |
| param2 | Name of the service that did not connect. |
Common benign sources
- Slow services at boot on busy or under-provisioned servers and VMs.
- Hung services after failed updates.
What attackers do that produces it
- Remote command execution through a temporary service whose binary path is a command line, producing 7045, 7009 and 7000 in quick succession.
Investigation tips
- Check for a 7045 for the same service in the preceding minute and read its
ImagePath. - Search process creation around the 7045 time for children of
services.exe(cmd.exe,powershell.exe). - Identify the source host via 4624 type 3 logons and 5145
svcctlpipe access just before.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1569.002 System Services: Service Execution | Execution |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.