System Shutdown/Reboot T1529

Tactic: Impact

Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems. Operating systems may contain commands to initiate a shutdown/reboot of a machine or network device. In some cases, these commands may also be used to initiate a shutdown/reboot of a remote computer or network device via Network Device CLI (e.g. reload). They may also include shutdown/reboot of a virtual machine via hypervisor / cloud consoles or command line tools.

Events covered

9 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 35 rules share fields, values, and exclusions.

Fields filtered most (29 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine8contains 8, in 3, ends_with 1* -f*, * -t*, echo b > , * -l*, * -r*
ControlName_s7eq 7ApplicationNotUsingClientCredentials, AzureSecureScoreAdminMFAV2, AzureSecureScoreOneAdmin, AzureSecureScoreRoleOverlap, AzureSecureScoreSelfServicePasswordReset
Image5ends_with 5\shutdown.exe, /esxcli, /halt, /launchctl, /reboot
SyslogMessage4contains 4vmpoweredoffevent, free space, patch store disk, temp directory
process_name4eq 3, in 1shutdown.exe, bash, dash, sudo
EventType3contains 2, eq 1asset down, baseline deviation, exec
OriginalFileName3eq 3shutdown.exe
sourcetype3eq 2, in 1auditd, azure:monitor:activity, vmw-syslog, vmware:esxlog*
type3eq 3path, cwd, execve
EventOriginalType2contains 2asset down, baseline deviation
azure.activitylogs.operation_name2eq 2microsoft.kubernetes/connectedclusters/pods/delete, microsoft.resources/subscriptions/resourcegroups/delete
data_stream.dataset2eq 2azure.activitylogs
event.outcome2eq 2success
sp2lt 210, 100
DbAction1eq 1shutdown

Top indicator values (99 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
CommandLinecontains
shutdown
34
CommandLinecontains
echo b >
1
CommandLinecontains
-9
1
CommandLinecontains
-kill
1
CommandLinecontains
/l
1
CommandLinecontains
/r
1
CommandLinecontains
/s
13
CommandLinecontains
disable
113
CommandLinecontains
kill
1
CommandLinecontains
remove
14
CommandLinecontains
sigkill
1
CommandLinecontains
stop
18
CommandLinecontains
unload
15
CommandLinecontains
vm process
12
CommandLinein
* -f*
33
CommandLinein
* -t*
33
CommandLinein
* /f*
35
CommandLinein
* /t*
34
CommandLinein
* -l*
1
CommandLinein
* -r*
12
CommandLinein
* -s*
12
CommandLinein
* /l*
1
OriginalFileNameeq
shutdown.exe
33
process_nameeq
shutdown.exe
34
Imageends_with
\shutdown.exe
22
SyslogMessagecontains
vmpoweredoffevent
23
data_stream.dataseteq
azure.activitylogs
239
event.outcomeeq
success
2369
typeeq
path
219
CommandLineends_with
/proc/sysrq-trigger
1

Exclusions (1 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
usereq
0
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 9 rules

Elastic 2 rules

Splunk 9 rules

Kusto 15 rules