Link Search Menu Expand Document

7045


Log Name : System
Event ID : 7045
Description : A new Service was installed on the system.

Table of contents

  1. What are Services
    1. Service Start Types
  2. Benifits of using Services
  3. Example of Malicious 7045 events
  4. Forensic

What are Services

Windows services are applications that run in the background without user interaction / does not interact with the desktop (by default) . A service is used to listen/respond to events, perform automated tasks (like windows update). All EDR/MDR agents are installed as service only (most of them).

Service Start Types

Automatic (Delayed Start)AutomaticManualDisabled

Benifits of using Services

  • A service starts when the system boots up
  • Runs with high privileges
  • A service runs in the background and very effictive over network as it uses windows native api.

Example of Malicious 7045 events

Service NameService PathComputerUser
637c804c:\windows\temp\95.batVictim-ComputerLocalAccount
eaa241f\\10.100.100.62\ADMIN$\eaa241f.exeVictim-ComputerSystem
9df3724%COMSPEC% /b /c start /b /min powershell -nop -w hidden -encodedcommand <base64-encoded-command>Victim-ComputerUser
Windows UpdateC:\beacon.exeVictim-ComputerSystem

Forensic