4697
A service was installed in the system
- Log: Security
- Source: Microsoft-Windows-Security-Auditing
- Tampering & persistence
- Warning
What it means
A new Windows service was installed. System event 7045 records the same thing.
Why it matters
Remote-admin tools and many attack tools install a service to run.
What to do
- Check the Service File Name path; temp folders and random names are red flags.
Find it with PowerShell
Get-WinEvent -MaxEvents 20 -FilterHashtable @{
LogName = 'Security'; Id = 4697
} | Select-Object TimeCreated, ProviderName, MessageAdd -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.
Source
Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.
Talk to us