System Event ID 7031: Service crashed (recovery action)
- Event ID
- 7031
- Channel
- System
- Provider
- Service Control Manager
- Log file
- System.evtx
- Category
- Services
- Default logging
- Logged by default
What event 7031 means
Event 7031 is written when a service process ends without the service reporting a stop, and the service has a recovery action configured. param1 is the service display name, param2 how many times this has happened, param3 the delay in milliseconds before the action, and param4 the action itself (for example restarting the service).
Its sibling 7034 is logged for the same situation when no recovery action is configured. Both mean the service process died: a crash, an out-of-memory condition, or something killing it.
For defenders, the important case is a security product or logging service dying: tools that terminate EDR processes, or attackers using taskkill /f on an agent, leave 7031/7034 rather than a clean 7036 stopped. Many agents restart themselves, so a single 7031 followed by 7036 running may be the only trace.
When it is logged
Always logged to the System log.
Key fields
| Field | What it tells you |
|---|---|
| param1 | Display name of the service that terminated. |
| param2 | Number of times the service has terminated unexpectedly. |
| param3 | Delay before the corrective action, in milliseconds. |
| param4 | Corrective action, e.g. restarting the service. |
Common benign sources
- Buggy or overloaded services crashing and being restarted.
- Services killed during software updates.
What attackers do that produces it
- Security agents, Sysmon or backup services killed with
taskkill /f, process-killing tools or vulnerable drivers. - Exploitation of a service that crashes it (repeated 7031 for the same service).
Investigation tips
- Check whether the service is a security, logging or backup component.
- Look at Application 1000 (crash) for the same process; no crash record suggests it was killed.
- Search process creation (4688, Sysmon 1) and new drivers (7045) just before for the killer.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.