Endpoint
Windows Service Control Manager
About 7,500 selected System-channel records/day from 18 workstations and six servers, with rendered native XML and ECS fields.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/windows-service-control-manager/generator.yml \
--id scm \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| 7036 | Service running or stopped | 88.7% | process |
| 7040 | Start type changed | 9.4% | configuration |
| 7045 | Service installed | 1.7% | configuration |
| 7034 | Unexpected termination | 0.2% | process |
Realism Features
- Temporary automatic-start settings usually return to demand start within about 5–18 minutes; another configuration may return them sooner
- Ordinary runs continue during episodes, with the same restoration policy
- Selected English SCM records; removals between package deployments and other SCM event classes are omitted
Sample Output
{
"@timestamp": "2026-09-21T01:30:58.391Z",
"ecs": {
"version": "8.11.0"
},
"event": {
"code": "7045",
"dataset": "system.system",
"kind": "event",
"original": "\u003cEvent xmlns=\u0027http://schemas.microsoft.com/win/2004/08/events/event\u0027\u003e\u003cSystem\u003e\u003cProvider Name=\u0027Service Control Manager\u0027 Guid=\u0027{555908d1-a6d7-4695-8e1e-26931d2012f4}\u0027 EventSourceName=\u0027Service Control Manager\u0027/\u003e\u003cEventID Qualifiers=\u002716384\u0027\u003e7045\u003c/EventID\u003e\u003cVersion\u003e0\u003c/Version\u003e\u003cLevel\u003e4\u003c/Level\u003e\u003cTask\u003e0\u003c/Task\u003e\u003cOpcode\u003e0\u003c/Opcode\u003e\u003cKeywords\u003e0x8080000000000000\u003c/Keywords\u003e\u003cTimeCreated SystemTime=\u00272026-09-21T01:30:58.391607000Z\u0027/\u003e\u003cEventRecordID\u003e433609\u003c/EventRecordID\u003e\u003cCorrelation/\u003e\u003cExecution ProcessID=\u0027880\u0027 ThreadID=\u00273632\u0027/\u003e\u003cChannel\u003eSystem\u003c/Channel\u003e\u003cComputer\u003eWS-HR-01.corp.contoso.com\u003c/Computer\u003e\u003cSecurity UserID=\u0027S-1-5-18\u0027/\u003e\u003c/System\u003e\u003cEventData\u003e\u003cData Name=\u0027ServiceName\u0027\u003eLitware Remote Support\u003c/Data\u003e\u003cData Name=\u0027ImagePath\u0027\u003eC:\\ProgramData\\Litware\\lrsvc.exe\u003c/Data\u003e\u003cData Name=\u0027ServiceType\u0027\u003euser mode service\u003c/Data\u003e\u003cData Name=\u0027StartType\u0027\u003edemand start\u003c/Data\u003e\u003cData Name=\u0027AccountName\u0027\u003eLocalSystem\u003c/Data\u003e\u003c/EventData\u003e\u003cRenderingInfo Culture=\u0027en-US\u0027\u003e\u003cMessage\u003eA service was installed in the system.\n\nService Name: Litware Remote Support\nService File Name: C:\\ProgramData\\Litware\\lrsvc.exe\nService Type: user mode service\nService Start Type: demand start\nService Account: LocalSystem\u003c/Message\u003e\u003cLevel\u003eInformation\u003c/Level\u003e\u003cTask\u003e\u003c/Task\u003e\u003cOpcode\u003e\u003c/Opcode\u003e\u003cChannel\u003e\u003c/Channel\u003e\u003cProvider\u003eMicrosoft-Windows-Service Control Manager\u003c/Provider\u003e\u003cKeywords\u003e\u003cKeyword\u003eClassic\u003c/Keyword\u003e\u003c/Keywords\u003e\u003c/RenderingInfo\u003e\u003c/Event\u003e",
"provider": "Service Control Manager"
},
"host": {
"name": "WS-HR-01.corp.contoso.com"
},
"log": {
"level": "information"
},
"message": "A service was installed in the system.\n\nService Name: Litware Remote Support\nService File Name: C:\\ProgramData\\Litware\\lrsvc.exe\nService Type: user mode service\nService Start Type: demand start\nService Account: LocalSystem",
"winlog": {
"api": "wineventlog",
"channel": "System",
"computer_name": "WS-HR-01.corp.contoso.com",
"event_data": {
"AccountName": "LocalSystem",
"ImagePath": "C:\\ProgramData\\Litware\\lrsvc.exe",
"ServiceName": "Litware Remote Support",
"ServiceType": "user mode service",
"StartType": "demand start"
},
"event_id": "7045",
"keywords": [
"Classic"
],
"opcode": "Info",
"process": {
"pid": 880,
"thread": {
"id": 3632
}
},
"provider_guid": "{555908d1-a6d7-4695-8e1e-26931d2012f4}",
"provider_name": "Service Control Manager",
"record_id": "433609",
"user": {
"domain": "NT AUTHORITY",
"identifier": "S-1-5-18",
"name": "SYSTEM",
"type": "Well Known Group"
}
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Include recurring correlated service deployments |
| anomaly_interval_hours | 24 | Episode interval in hours, from 2 to 8760 |
| dns_domain | corp.contoso.com | Hostname DNS suffix |
| ad_domain | CONTOSO | Administrator account domain |
Related Generators
Endpoint
Windows Security Event Log
The Security channel of Windows Event Log — logon/logoff sessions, process creation, privilege escalation, account management, and audit policy changes from a 120-host Active Directory fleet.
Endpoint
Windows PowerShell
PowerShell classic and operational channels — engine lifecycle, script block logging, module invocations, pipeline execution, and provider starts. Includes obfuscated command detection and suspicious script patterns.
Endpoint
Windows Sysmon
Sysmon (System Monitor) operational channel — process creation with full command lines, network connections, file creates, registry modifications, DNS queries, and WMI events. SwiftOnSecurity-style tuning.