inquiry About Services Installed (Event ID 7045)

Archana suresh 0 Reputation points
2025-08-18T18:43:19.2433333+00:00

Hi,

For Event ID 7045 (A service was installed in the system), we’ve observed the installation of the following services:

  • system_monitor Path: \SystemRoot\system32\DRIVERS\system_monitor.sys
  • RegCacheFilter Path: system32\DRIVERS\RegCacheFilter.sys
  • file_monitor Service name: file_monitor Startup type: Auto start Driver path: system32\DRIVERS\file_monitor.sys

The system_monitor, RegCacheFilter, and file_monitor drivers have generic names and are not clearly tied to a known vendor, which raises concerns about potential misuse or unauthorized persistence mechanisms.

Could you please confirm:

Whether these services are part of any approved tooling?

If there is any reason to treat these as suspicious or investigate further?

Please let us know if you need additional context or logs

Microsoft Security | Windows Autopilot
0 comments No comments
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.