Skip to content
System

System Event ID 7036: Service state changed

The service entered the running or stopped stateSystem event 7036 logs each time a service enters the running or stopped state. Shows when services ran and when security tools or logging were stopped.
7036
Event ID
7036
Channel
System
Provider
Service Control Manager
Log file
System.evtx
Category
Services
Default logging
Logged by default

What event 7036 means

Event 7036 is written by the Service Control Manager whenever a service changes state. param1 is the service display name and param2 the new state, most often running or stopped. It is by far the most frequent Service Control Manager event, since many services start and stop on demand.

Its value comes from correlation. After a 7045, a running / stopped pair seconds apart is the typical footprint of one-shot remote execution (PsExec-style). Before an encryption or wiping phase, a series of stopped records for backup, database and security services is a classic ransomware preparation step. A security agent or the Windows Event Log reaching stopped outside a shutdown is a red flag.

The event does not say who stopped the service. Find that in process creation (4688, Sysmon 1: sc stop, net stop, Stop-Service, taskkill) at the same time.

When it is logged

Audit policy / configuration

Always logged to the System log.

Very noisy. The state text in param2 can be localized on non-English systems, and the record's binary data holds the service key name.

Key fields

FieldWhat it tells you
param1Display name of the service, e.g. Windows Defender Antivirus Service, Volume Shadow Copy.
param2New state of the service.
ValueMeaning
runningThe service started.
stoppedThe service stopped, cleanly or on request.

Common benign sources

  • Demand-start services starting and stopping all day (Windows Update, BITS, Windows Modules Installer).
  • Services stopped and restarted during patching and software updates.

What attackers do that produces it

  • Remote execution services (PSEXESVC or random names) entering running then stopped right after their 7045 installation.
  • Ransomware stopping backup, SQL, Exchange, VSS and antivirus services before encryption.
  • Defense evasion by stopping EDR, Defender or Sysmon services.

Investigation tips

  • Filter out the noisy demand-start services, then look for security, backup and logging services entering stopped.
  • Pair running/stopped records with 7045 to measure how long an installed service ran.
  • Find the command that stopped the service in 4688 or Sysmon 1 at the same second.

MITRE ATT&CK techniques

TechniqueTactics
T1489 Service StopImpact
T1569.002 System Services: Service ExecutionExecution
T1685 Disable or Modify ToolsDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

3 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1
  • Medium · 2

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideEvent ID 7036 explained: service state changes for DFIR triage

Sources and further reading