System Event ID 7045: Service installed
- Event ID
- 7045
- Channel
- System
- Provider
- Service Control Manager
- Log file
- System.evtx
- Category
- Services
- Default logging
- Logged by default
What event 7045 means
Event 7045 is written by the Service Control Manager when a new service is created — through sc create, New-Service, an installer, the CreateService API or remotely over the SCM RPC interface. Kernel drivers registered as services appear here too. Unlike Security 4697, it is logged by default, which makes it one of the most reliable persistence and lateral movement artifacts on Windows.
ImagePath is the field to read first. Legitimate services point to signed binaries under C:\Windows\System32 or C:\Program Files. Paths in C:\Windows\Temp, user profiles, C:\ProgramData or ADMIN$, and command lines such as cmd.exe /c ..., %COMSPEC% or powershell -enc ..., are strong indicators of remote execution tools and malware. Random 8-character or GUID-like service names are typical of Impacket, Metasploit and Cobalt Strike service-based execution.
Remote execution through the SCM (PsExec and its clones) leaves a 7045 on the target host, usually right after a type 3 logon (4624) from the source, then 7036 as the service starts and stops.
When it is logged
Always logged to the System log when a service is installed.
Security 4697 carries similar data but requires Audit Security System Extension. A 7045 is only written at creation; changes to an existing service's binary path do not produce one.
Key fields
| Field | What it tells you | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ServiceName | Display name of the new service. PSEXESVC, random letters or GUID-like names deserve attention. | ||||||||||||
| ImagePath | Binary path or command line the service will run. Look for temp folders, user directories, cmd.exe /c, powershell, rundll32, mshta or UNC paths. | ||||||||||||
| ServiceType | Type of service.
| ||||||||||||
| StartType | When the service starts.
| ||||||||||||
| AccountName | Account the service runs as, e.g. LocalSystem, NT AUTHORITY\LocalService or a domain account. Empty for drivers. |
Common benign sources
- Software installers and updates registering their services and drivers.
- Endpoint agents, backup and remote support tools deployed by IT.
- Hardware drivers installed when new devices are connected.
- Legitimate PsExec use by administrators (service
PSEXESVC).
What attackers do that produces it
- Remote execution with PsExec, Impacket
psexec.py/smbexec.py, Metasploit or Cobalt Strikejump psexec: short-lived services with random names orcmd.exe /cinImagePath. - Persistence via a new auto-start service pointing to a dropped payload.
- Loading a vulnerable signed driver (BYOVD) to disable EDR, visible as a new kernel mode driver.
Investigation tips
- Review every 7045 on the timeline; the volume is low enough to read them all.
- Check
ImagePathlocation, signature and hash; retrieve the binary if it still exists. - Correlate with 4624 type 3 and 5145 (ADMIN$ / IPC$
svcctl) just before on the same host to identify the source. - Follow with 7036 (running/stopped), 7009 or 7000 (start failures) to see whether it ran and for how long.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
41 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.
- Critical · 2
- High · 22
- Medium · 17
- CriticalCobaltStrike Service Installations - SystemRule by Florian Roth (Nextron Systems), Wojciech Lesicki, SigmaHQ, DRL 1.1
- CriticalMoriya Rootkit - SystemRule by Bhabesh Raj, SigmaHQ, DRL 1.1
- HighCredential Dumping Tools Service Execution - SystemRule by Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, SigmaHQ, DRL 1.1
- HighHackTool Service Registration or ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation CLIP+ Launcher - SystemRule by Jonathan Cheong, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Obfuscated IEX Invocation - SystemRule by Daniel Bohannon (@Mandiant/@FireEye), oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation STDIN+ Launcher - SystemRule by Jonathan Cheong, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation VAR+ Launcher - SystemRule by Jonathan Cheong, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - SystemRule by Timur Zinniatullin, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Via Stdin - SystemRule by Nikita Nazarov, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Via Use Clip - SystemRule by Nikita Nazarov, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Via Use MSHTA - SystemRule by Nikita Nazarov, oscd.community, SigmaHQ, DRL 1.1
- HighInvoke-Obfuscation Via Use Rundll32 - SystemRule by Nikita Nazarov, oscd.community, SigmaHQ, DRL 1.1
- HighKrbRelayUp Service InstallationRule by Sittikorn S, Tim Shelton, SigmaHQ, DRL 1.1
- HighMeterpreter or Cobalt Strike Getsystem Service Installation - SystemRule by Teymur Kheirkhabarov, Ecco, Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighPowerShell Scripts Installed as ServicesRule by oscd.community, Natalia Shornikova, SigmaHQ, DRL 1.1
- HighProcessHacker Privilege ElevationRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighRTCore Suspicious Service InstallationRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighService Installation with Suspicious Folder PatternRule by pH-T (Nextron Systems), SigmaHQ, DRL 1.1
- HighService Installed By Unusual Client - SystemRule by Tim Rauch (Nextron Systems), Elastic (idea), SigmaHQ, DRL 1.1
- HighSliver C2 Default Service InstallationRule by Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- Highsmbexec.py Service InstallationRule by Omer Faruk Celik, SigmaHQ, DRL 1.1
- HighSuspicious Service InstallationRule by pH-T (Nextron Systems), Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighSuspicious Service Installation ScriptRule by pH-T (Nextron Systems), SigmaHQ, DRL 1.1
- MediumAnydesk Remote Access Software Service InstallationRule by Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.