Windows Service Terminated With Error (Service Control Manager Event 7023)

Alerts on Windows services terminated with an error as reported by the Service Control Manager (EventID 7023).

FreeReviewedSigma · Low · v2
Product
windows
Service
system
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-04-14
Updated
2026-07-31

What it detects

This rule matches Windows System logs where the Service Control Manager reports that an X service terminated with the following error (EventID 7023). Service termination can be an indicator of abnormal execution, persistence attempts, or disruption activity, making these events valuable for correlating with other host and process telemetry. It relies on Windows service infrastructure logging fields for Provider_Name and EventID.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.