Skip to content
System

System Event ID 7045: Service installed

A service was installed in the systemSystem event 7045 records every new service or driver: name, binary path, start type and account. A top lateral movement signal.
7045
Event ID
7045
Channel
System
Provider
Service Control Manager
Log file
System.evtx
Category
Services
Default logging
Logged by default

What event 7045 means

Event 7045 is written by the Service Control Manager when a new service is created — through sc create, New-Service, an installer, the CreateService API or remotely over the SCM RPC interface. Kernel drivers registered as services appear here too. Unlike Security 4697, it is logged by default, which makes it one of the most reliable persistence and lateral movement artifacts on Windows.

ImagePath is the field to read first. Legitimate services point to signed binaries under C:\Windows\System32 or C:\Program Files. Paths in C:\Windows\Temp, user profiles, C:\ProgramData or ADMIN$, and command lines such as cmd.exe /c ..., %COMSPEC% or powershell -enc ..., are strong indicators of remote execution tools and malware. Random 8-character or GUID-like service names are typical of Impacket, Metasploit and Cobalt Strike service-based execution.

Remote execution through the SCM (PsExec and its clones) leaves a 7045 on the target host, usually right after a type 3 logon (4624) from the source, then 7036 as the service starts and stops.

When it is logged

Audit policy / configuration

Always logged to the System log when a service is installed.

Security 4697 carries similar data but requires Audit Security System Extension. A 7045 is only written at creation; changes to an existing service's binary path do not produce one.

Key fields

FieldWhat it tells you
ServiceNameDisplay name of the new service. PSEXESVC, random letters or GUID-like names deserve attention.
ImagePathBinary path or command line the service will run. Look for temp folders, user directories, cmd.exe /c, powershell, rundll32, mshta or UNC paths.
ServiceTypeType of service.
ValueMeaning
user mode serviceNormal service running a user-mode executable.
kernel mode driverKernel driver. Unexpected drivers can be rootkits or vulnerable drivers loaded to kill security tools.
file system driverFile system or filter driver.
StartTypeWhen the service starts.
ValueMeaning
auto startStarts at every boot — persistence.
demand startManual start; typical of one-shot remote execution services.
disabledCannot be started until reconfigured.
boot startDriver loaded by the boot loader.
system startDriver loaded during kernel initialization.
AccountNameAccount the service runs as, e.g. LocalSystem, NT AUTHORITY\LocalService or a domain account. Empty for drivers.

Common benign sources

  • Software installers and updates registering their services and drivers.
  • Endpoint agents, backup and remote support tools deployed by IT.
  • Hardware drivers installed when new devices are connected.
  • Legitimate PsExec use by administrators (service PSEXESVC).

What attackers do that produces it

  • Remote execution with PsExec, Impacket psexec.py / smbexec.py, Metasploit or Cobalt Strike jump psexec: short-lived services with random names or cmd.exe /c in ImagePath.
  • Persistence via a new auto-start service pointing to a dropped payload.
  • Loading a vulnerable signed driver (BYOVD) to disable EDR, visible as a new kernel mode driver.

Investigation tips

  • Review every 7045 on the timeline; the volume is low enough to read them all.
  • Check ImagePath location, signature and hash; retrieve the binary if it still exists.
  • Correlate with 4624 type 3 and 5145 (ADMIN$ / IPC$ svcctl) just before on the same host to identify the source.
  • Follow with 7036 (running/stopped), 7009 or 7000 (start failures) to see whether it ran and for how long.

MITRE ATT&CK techniques

TechniqueTactics
T1543.003 Create or Modify System Process: Windows ServicePersistence, Privilege Escalation
T1569.002 System Services: Service ExecutionExecution
T1021.002 Remote Services: SMB/Windows Admin SharesLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

41 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.

  • Critical · 2
  • High · 22
  • Medium · 17

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideEvent ID 7045: A service was installed in the system

Sources and further reading