New service installed. ServiceName, ServiceFileName, ServiceType, ServiceStartType, ServiceAccount are key. Counterpart to Security 4697.
Primary persistence indicator for service-based attacks. PsExec creates a temporary service (PSEXESVC or custom name) on the remote host. Ransomware installs as a service. Cobalt Strike creates services for lateral movement. ServiceFileName in temp or user paths is the key suspicious indicator.
Alert: ServiceFileName in %TEMP%, %APPDATA%, C:\Users\, \\UNC\\ paths. Alert: ServiceAccount=LocalSystem for user-installed services. Alert: service names that are random characters or mimic legitimate Windows services. Cross-reference with Security 4697.
ServiceNameImagePathServiceTypeStartTypeAccountName | Tactic | Technique |
|---|---|
| Persistence | Windows Service (T1543.003) |
Starting points — adapt the log source, projected fields and thresholds for your environment.
title: New Service Installed from Suspicious Path
status: stable
description: Service installed from temp or user-writable directory
author: theadminstack.com
date: 2026/05/16
logsource:
product: windows
service: system
detection:
selection:
EventID: 7045
filter_legit:
ServiceFileName|startswith:
- 'C:\\Windows\\'
- 'C:\\Program Files\\'
- 'C:\\Program Files (x86)\\'
condition: selection and not filter_legit
falsepositives:
- Software installations
- IT management agents
level: high
tags:
- attack.persistence
- attack.t1543.003
Event
| where EventLog == "System" and EventID == 7045 // A new service was installed in the system
// EventData holds: ServiceName, ImagePath, ServiceType, StartType, AccountName
| project TimeGenerated, Computer, RenderedDescription
| sort by TimeGenerated desc
index=* sourcetype="WinEventLog:System" EventCode=7045
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count `# A new service was installed in the system — add EventData fields: ServiceName, ImagePath, ServiceType, StartType`
A new service was installed in the system. New service installed. ServiceName, ServiceFileName, ServiceType, ServiceStartType, ServiceAccount are key. Counterpart to Security 4697.
Event 7045 is written to the System channel by Service Control Manager / Kernel. Logged by default in the System channel; no audit policy required.
Event 7045 is associated with: Windows Service (T1543.003).
Alert: ServiceFileName in %TEMP%, %APPDATA%, C:\Users\, \\UNC\\ paths. Alert: ServiceAccount=LocalSystem for user-installed services. Alert: service names that are random characters or mimic legitimate Windows services. Cross-reference with Security 4697.