inquiry About Services Installed (Event ID 7045)
Archana suresh
0
Reputation points
Hi,
For Event ID 7045 (A service was installed in the system), we’ve observed the installation of the following services:
- system_monitor Path:
\SystemRoot\system32\DRIVERS\system_monitor.sys - RegCacheFilter Path:
system32\DRIVERS\RegCacheFilter.sys - file_monitor Service name:
file_monitorStartup type: Auto start Driver path:system32\DRIVERS\file_monitor.sys
The system_monitor, RegCacheFilter, and file_monitor drivers have generic names and are not clearly tied to a known vendor, which raises concerns about potential misuse or unauthorized persistence mechanisms.
Could you please confirm:
Whether these services are part of any approved tooling?
If there is any reason to treat these as suspicious or investigate further?
Please let us know if you need additional context or logs
Microsoft Security | Windows Autopilot
Sign in to answer