Skip to content
System

System Event ID 7040: Service start type changed

The start type of the service was changedSystem event 7040 records a change to a service start type (auto, demand, disabled). Reveals security tools being disabled and services turned into persistence.
7040
Event ID
7040
Channel
System
Provider
Service Control Manager
Log file
System.evtx
Category
Services
Default logging
Logged by default

What event 7040 means

Event 7040 is written when a service's start type is changed — via sc config <svc> start= ..., Set-Service -StartupType, the Services console, Group Policy or the service's own installer. param1 is the display name, param2 the old start type, param3 the new one and param4 the service key name.

Most changes are benign: Windows itself toggles services such as BITS, Delivery Optimization or Windows Update between demand and automatic start all the time. The user SID in the record's System section shows the account that made the change, typically a built-in service account for those self-toggling services. The interesting ones are changes to disabled for security, backup or logging services, and changes to auto start for services the attacker controls.

Like 7036, the record does not include the command line. Correlate the timestamp with process creation to find who made the change.

When it is logged

Audit policy / configuration

Always logged to the System log.

Changes to the service binary path (sc config binPath=) do not produce 7040; watch the service's registry key (Sysmon 13, Security 4657) for those.

Key fields

FieldWhat it tells you
param1Display name of the service.
param2Previous start type (auto start, demand start, disabled, boot start, system start).
param3New start type. disabled on a security service is the pattern to hunt.
param4Service key name under HKLM\SYSTEM\CurrentControlSet\Services, e.g. DoSvc, WinDefend.

Common benign sources

  • Windows Update, BITS and Delivery Optimization toggling their own start type.
  • Administrators and GPOs hardening a baseline by disabling unused services.

What attackers do that produces it

  • Disabling Defender, EDR agents, Windows Event Log, VSS or backup services before an attack (sc config ... start= disabled).
  • Setting an attacker-controlled or abused service to auto start for persistence.
  • Re-enabling a disabled remote access service such as Remote Registry or Terminal Services.

Investigation tips

  • Filter out changes by built-in accounts (S-1-5-18, S-1-5-20) to well-known self-toggling services, then review the rest.
  • Prioritize param3 = disabled for security and logging services and auto start for rare services.
  • Find the command in 4688 or Sysmon 1 (sc.exe config, Set-Service) and the user behind it.

MITRE ATT&CK techniques

TechniqueTactics
T1685 Disable or Modify ToolsDefense Impairment
T1489 Service StopImpact
T1543.003 Create or Modify System Process: Windows ServicePersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading