Windows System Service Control Manager Event 7045 Scheduled Scan and UpdatMachine

Alerts on Windows service installation events for persistence-related scheduled services named SC Scheduled Scan or UpdatMachine.

FreeReviewedSigma · Critical · v5
Product
windows
Service
system
Author
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community (SigmaHQ), DRL 1.1
Published
2018-03-23
Updated
2026-07-31

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. Exfiltration

  10. Impact

What it detects

This rule identifies creation or configuration of Windows services via Service Control Manager (EventID 7045) for the specific service names "SC Scheduled Scan" and "UpdatMachine." Attackers can use scheduled service-based execution to establish persistence or repeated execution under the Windows Service infrastructure. Telemetry relies on Windows System logs capturing SCM events and the service name field for EventID 7045.

Related detections9 linkedT1112 — drag to rearrange
Windows Registry Persistence via UMe/UT Run Keys
Windows Security: Detect Scheduled Task Creation for OilRig-Related Persistence
Windows Scheduled Task Process Creating autoit3.exe for nslookup TXT Queries (OilRig)
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Malicious Impacket SMBexec Service Creation - Registry (via registry_event)
Malicious Impacket SMBexec Service Registration - Native (via security)
Suspicious Hidden Scheduled Task via TaskCache Security Descriptor Manipulation
Suspicious Windows Service Trigger Configuration via Registry Modification
Suspicious Service Persistence Masquerading as DevQueryBrokerService
Windows System Service Control Manager Event 7045 Scheduled Scan and UpdatMachine
Pivot detection · T1112 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.