7036 System log · Service Control Manager medium severity medium volume

System Event ID 7036 — The service entered the stopped/running state

Service started or stopped. ServiceName and State (running/stopped) are key. Very high signal-to-noise when filtered to security-relevant services.

Why event 7036 matters

Attackers stop security services before major attack phases: AV stopped before deploying ransomware, EDR agent stopped before credential dumping. Also captures: PsExec service appearing and stopping (lateral movement pattern), attacker-created service lifecycle.

How to detect it

Alert: State=Stopped for AV, EDR, backup, or monitoring services. Alert: unknown service names entering 'running' state (attacker-created services). Alert: rapid service start-stop cycles (service used briefly then cleaned up = attack tool pattern). Build a baseline of expected service names.

Log source
System
Logged by default in the System channel; no audit policy required.
Fields to pivot on
param1param2

MITRE ATT&CK mapping

Tactic Technique
Defense Evasion Disable or Modify Tools (T1562.001)

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sigma rule
title: Security Service Stopped
status: stable
description: Critical security service stopped unexpectedly
author: theadminstack.com
date: 2026/05/16
logsource:
    product: windows
    service: system
detection:
    selection:
        EventID: 7036
        param2: 'stopped'
        param1|contains:
            - 'Windows Defender'
            - 'Windows Security'
            - 'CrowdStrike'
            - 'Sysmon'
            - 'EventLog'
    condition: selection
falsepositives:
    - Planned maintenance
    - Software updates
level: high
tags:
    - attack.defense_evasion
    - attack.t1562.001
Sentinel / Defender KQL
Event
| where EventLog == "System" and EventID == 7036   // The service entered the stopped/running state
// EventData holds: param1, param2
| project TimeGenerated, Computer, RenderedDescription
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:System" EventCode=7036
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# The service entered the stopped/running state — add EventData fields: param1, param2`
Hunt event 7036 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related Service Control Manager events

7000 The service failed to start due to the following error 7001 The service depends on another service 7009 A timeout was reached while waiting for service to connect 7022 The service hung on starting 7023 The service terminated with an error 7024 The service terminated with a service-specific error 7026 The following boot-start or system-start driver failed to load 7031 The service terminated unexpectedly 7034 The service terminated unexpectedly and will be restarted 7035 The service was successfully sent a start or stop control 7038 The service was unable to log on as the configured account 7040 The start type of a service was changed

Frequently asked questions

What is System Event ID 7036?

The service entered the stopped/running state. Service started or stopped. ServiceName and State (running/stopped) are key. Very high signal-to-noise when filtered to security-relevant services.

Which log records event 7036?

Event 7036 is written to the System channel by Service Control Manager / Kernel. Logged by default in the System channel; no audit policy required.

What MITRE ATT&CK techniques map to event 7036?

Event 7036 is associated with: Disable or Modify Tools (T1562.001).

How do you detect activity around event 7036?

Alert: State=Stopped for AV, EDR, backup, or monitoring services. Alert: unknown service names entering 'running' state (attacker-created services). Alert: rapid service start-stop cycles (service used briefly then cleaned up = attack tool pattern). Build a baseline of expected service names.