Availability-critical Windows service terminating unexpectedly
AN0850 describes exploitation followed by a service crash, restart or repeated failure, and only the last part of that has an observable in the brief's log sources. This rule takes the System channel leg: the Service Control Manager reporting that a service died without having been sent a control request (EventID 7031 and 7034), scoped by display-name fragment to the web, database and remote-access tiers whose loss is the denial of availability this sub-technique is about. The other two legs cannot carry the behaviour. Sysmon EventID 1 is a launch record with no crash, fault or resource field, and Application EventID 1000 exposes the faulting binary only through unnamed Data elements with no field vocabulary this corpus can rely on. Note what the SCM does not see: a worker process killed by an exploit is not a service termination. An IIS application pool dying takes w3wp.exe with it and is reported by WAS on this same System channel under the Microsoft-Windows-WAS provider, not by the Service Control Manager, so the two IIS fragments below match only if the W3SVC or IISADMIN host process itself dies — the commonest web-exploitation crash on this platform is invisible here, and the same holds for any engine that isolates work in child processes. MITRE's TargetApplication knob names the tier to watch and is populated here with a generic starter list that every site must replace with its own service display names; MITRE's TimeWindow knob asks for repetition (for example five crashes in an hour), and lib/sigma models no aggregation, no timeframe and no near, so the repetition that would separate a re-exploited persistent DoS from one bad afternoon is not expressed. A single match therefore means one critical service died uncommanded, not that anything was exploited. This is the same SCM signal the published T1687 rule uses; the two differ only in which services they name, T1687 watching defensive agents being degraded and this rule watching availability of the service tier, and their name lists do not overlap. Unlike the process-creation legs elsewhere in this brief, 7031 and 7034 need no audit policy — the SCM writes them by default. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0304, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full descriptionShow less
The detection
The 3 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.
detection.yml
title: Availability-critical Windows service terminating unexpectedlyid: 8566a296-824e-4277-beb1-27dd4dfa0a3dstatus: experimentaldescription: | AN0850 describes exploitation followed by a service crash, restart or repeated failure, and only the last part of that has an observable in the brief's log sources. This rule takes the System channel leg: the Service Control Manager reporting that a service died without having been sent a control request (EventID 7031 and 7034), scoped by display-name fragment to the web, database and remote-access tiers whose loss is the denial of availability this sub-technique is about. The other two legs cannot carry the behaviour. Sysmon EventID 1 is a launch record with no crash, fault or resource field, and Application EventID 1000 exposes the faulting binary only through unnamed Data elements with no field vocabulary this corpus can rely on. Note what the SCM does not see: a worker process killed by an exploit is not a service termination. An IIS application pool dying takes w3wp.exe with it and is reported by WAS on this same System channel under the Microsoft-Windows-WAS provider, not by the Service Control Manager, so the two IIS fragments below match only if the W3SVC or IISADMIN host process itself dies — the commonest web-exploitation crash on this platform is invisible here, and the same holds for any engine that isolates work in child processes. MITRE's TargetApplication knob names the tier to watch and is populated here with a generic starter list that every site must replace with its own service display names; MITRE's TimeWindow knob asks for repetition (for example five crashes in an hour), and lib/sigma models no aggregation, no timeframe and no near, so the repetition that would separate a re-exploited persistent DoS from one bad afternoon is not expressed. A single match therefore means one critical service died uncommanded, not that anything was exploited. This is the same SCM signal the published T1687 rule uses; the two differ only in which services they name, T1687 watching defensive agents being degraded and this rule watching availability of the service tier, and their name lists do not overlap. Unlike the process-creation legs elsewhere in this brief, 7031 and 7034 need no audit policy — the SCM writes them by default. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0304, not hand-written and not tested by its author. Any lab result is on this rule's own page.references: - https://attack.mitre.org/techniques/T1499/004 - https://attack.mitre.org/detectionstrategies/DET0304author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags: - attack.impact - attack.t1499.004logsource: product: windows service: systemdetection: selection: Provider_Name: 'Service Control Manager' EventID: - 7031 - 7034 param1|contains: - 'World Wide Web Publishing' - 'IIS Admin' - 'SQL Server' - 'MySQL' - 'PostgreSQL' - 'Apache' - 'Routing and Remote Access' - 'Remote Desktop Services' condition: selectionfalsepositives: - "Ordinary software faults in the service host itself. A database engine or an Apache service dies on its own from memory exhaustion, a corrupt configuration file, a full disk or a driver conflict after a patch, and the SCM records exactly this event with no adversary present — across any server fleet these are the majority of matches. Nothing in a single 7031 distinguishes a bug from an induced crash, which is why this rule is scored low." - "Abrupt power transitions and infrastructure operations. Forced shutdowns, hypervisor snapshot restores, live-migration failures and storage path flaps make the SCM record running services as terminated unexpectedly, usually several at once and often in scheduled maintenance windows." - "Product upgrades and patch installs that stop a service by killing it rather than through the control interface, so the SCM sees a termination it never asked for. A rollout across the fleet produces a burst of these within the same change window." - "Any service whose display name merely contains one of these fragments. Matching on Apache or SQL Server picks up unrelated third-party products that embed those words, including bundled instances a site does not consider availability-critical."level: lowSplunk · SPL
Run this as a search.
index=* (Provider_Name="Service Control Manager" AND (EventID="7031" OR EventID="7034") AND (param1="*World Wide Web Publishing*" OR param1="*IIS Admin*" OR param1="*SQL Server*" OR param1="*MySQL*" OR param1="*PostgreSQL*" OR param1="*Apache*" OR param1="*Routing and Remote Access*" OR param1="*Remote Desktop Services*"))Elastic · ES|QL
Run this as a search.
FROM logs-*| WHERE (TO_LOWER(winlog.provider_name) == "service control manager" AND (event.code == 7031 OR event.code == 7034) AND (TO_LOWER(winlog.event_data.param1) LIKE "*world wide web publishing*" OR TO_LOWER(winlog.event_data.param1) LIKE "*iis admin*" OR TO_LOWER(winlog.event_data.param1) LIKE "*sql server*" OR TO_LOWER(winlog.event_data.param1) LIKE "*mysql*" OR TO_LOWER(winlog.event_data.param1) LIKE "*postgresql*" OR TO_LOWER(winlog.event_data.param1) LIKE "*apache*" OR TO_LOWER(winlog.event_data.param1) LIKE "*routing and remote access*" OR TO_LOWER(winlog.event_data.param1) LIKE "*remote desktop services*"))
Wazuh · XML rule
Deploy to your manager — this is a rule, not a search.
<group name="sigma,windows,"> <!-- Rule ids must be unique on your manager; 100000+ is the user range. --> <rule id="100000" level="5"> <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. --> <field name="Provider_Name" type="pcre2">(?i)^Service Control Manager$</field> <field name="EventID" type="pcre2">(?i)(^7031$|^7034$)</field> <field name="param1" type="pcre2">(?i)(World Wide Web Publishing|IIS Admin|SQL Server|MySQL|PostgreSQL|Apache|Routing and Remote Access|Remote Desktop Services)</field> <description>Availability-critical Windows service terminating unexpectedly</description> <mitre> <id>T1499.004</id> </mitre> </rule></group>
Sentinel · KQL
Run this as a search.
Sentinel cannot express this construct. `param1` has no Sentinel column: System-channel message parameters live inside `ParameterXml`, not in a column of their own. The Sigma source is on the first tab, unchanged.
Verdicts · reactions · comments
Community
Verdicts from engineers who actually deployed it, and the conversation around it.
Nobody has run this in a real environment and said what happened.
Verdicts from engineers who deployed it
0 castNo verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.
Log in to report a verdict.
Log in to join the discussion.
No comments yet. Someone who deploys this will have something to say about it.