System Event ID 7036: Service state changed
- Event ID
- 7036
- Channel
- System
- Provider
- Service Control Manager
- Log file
- System.evtx
- Category
- Services
- Default logging
- Logged by default
What event 7036 means
Event 7036 is written by the Service Control Manager whenever a service changes state. param1 is the service display name and param2 the new state, most often running or stopped. It is by far the most frequent Service Control Manager event, since many services start and stop on demand.
Its value comes from correlation. After a 7045, a running / stopped pair seconds apart is the typical footprint of one-shot remote execution (PsExec-style). Before an encryption or wiping phase, a series of stopped records for backup, database and security services is a classic ransomware preparation step. A security agent or the Windows Event Log reaching stopped outside a shutdown is a red flag.
The event does not say who stopped the service. Find that in process creation (4688, Sysmon 1: sc stop, net stop, Stop-Service, taskkill) at the same time.
When it is logged
Always logged to the System log.
Very noisy. The state text in param2 can be localized on non-English systems, and the record's binary data holds the service key name.
Key fields
| Field | What it tells you | ||||||
|---|---|---|---|---|---|---|---|
| param1 | Display name of the service, e.g. Windows Defender Antivirus Service, Volume Shadow Copy. | ||||||
| param2 | New state of the service.
|
Common benign sources
- Demand-start services starting and stopping all day (Windows Update, BITS, Windows Modules Installer).
- Services stopped and restarted during patching and software updates.
What attackers do that produces it
- Remote execution services (PSEXESVC or random names) entering
runningthenstoppedright after their 7045 installation. - Ransomware stopping backup, SQL, Exchange, VSS and antivirus services before encryption.
- Defense evasion by stopping EDR, Defender or Sysmon services.
Investigation tips
- Filter out the noisy demand-start services, then look for security, backup and logging services entering
stopped. - Pair
running/stoppedrecords with 7045 to measure how long an installed service ran. - Find the command that stopped the service in 4688 or Sysmon 1 at the same second.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
3 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- Medium · 2
- HighHackTool Service Registration or ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- MediumRemote Access Tool Services Have Been Installed - SystemRule by Connor Martin, Nasreddine Bencherchali, SigmaHQ, DRL 1.1
- MediumWindows Defender Threat Detection Service DisabledRule by Ján Trenčanský, frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.