Technique.View on attack.mitre.org
Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems. Operating systems may contain commands to initiate a shutdown/reboot of a machine or network device. In some cases, these commands may also be used to initiate a shutdown/reboot of a remote computer or network device via Network Device CLI (e.g. reload). They may also include shutdown/reboot of a virtual machine via hypervisor / cloud consoles or command line tools.
Shutting down or rebooting systems may disrupt access to computer resources for legitimate users while also impeding incident response/recovery.
Adversaries may also use Windows API functions, such as `InitializeSystemShutdownExW` or `ExitWindowsEx`, to force a system to shut down or reboot. Alternatively, the `NtRaiseHardError`or `ZwRaiseHardError` Windows API functions with the `ResponseOption` parameter set to `OptionShutdownSystem` may deliver a “blue screen of death” (BSOD) to a system. In order to leverage these API functions, an adversary may need to acquire `SeShutdownPrivilege` (e.g., via Access Token Manipulation).
In some cases, the system may not be able to boot again.
Adversaries may attempt to shutdown/reboot a system after impacting it in other ways, such as Disk Structure Wipe or Inhibit System Recovery, to hasten the intended effects on system availability.
Rules on DetectionCode tagged with T1529.
| Rule | Level | Log source |
|---|---|---|
| Silence.EDA Detection | critical | windows / ps_script |
| Cisco Denial of Service | medium | cisco / NULL |
| ESXi VM Kill Via ESXCLI | medium | linux / process_creation |
| Potential Abuse of Linux Magic System Request Key | medium | linux / NULL |
| Suspicious Execution of Shutdown | medium | windows / process_creation |
| Suspicious Execution of Shutdown to Log Out | medium | windows / process_creation |
| System Shutdown/Reboot - Linux | informational | linux / NULL |
| System Shutdown/Reboot - MacOs | informational | macos / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| ESXi Bulk VM Termination | TTP | NULL | VMWare ESXi Syslog |
| Linux Magic SysRq Key Abuse | TTP | NULL | Linux Auditd Path, Linux Auditd Cwd |
| Linux System Reboot Via System Request Key | TTP | NULL | Sysmon for Linux EventID 1 |
| Microsoft Intune Manual Device Management | Hunting | NULL | Azure Monitor Activity |
| Windows Common Abused Cmd Shell Risk Behavior | Correlation | NULL | |
| Windows System LogOff Commandline | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows System Reboot CommandLine | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows System Shutdown CommandLine | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAPT37 | APT37 has used malware that will issue the command |
| GroupAPT38 | APT38 has used a custom MBR wiper named BOOTWRECK, which will initiate a system reboot after wiping the victim's MBR. |
| GroupLazarus Group | Lazarus Group has rebooted systems after destroying files and wiping the MBR on infected systems. |
| GroupMedusa Group | Medusa Group has manually turned off and encrypted virtual machines. |
| Used by | Procedure example |
|---|---|
| MalwareAcidPour | AcidPour includes functionality to reboot the victim system following wiping actions, similar to AcidRain. |
| MalwareAcidRain | AcidRain reboots the target system once the various wiping processes are complete. |
| MalwareApostle | Apostle reboots the victim machine following wiping and related activity. |
| MalwareAvosLocker | AvosLocker’s Linux variant has terminated ESXi virtual machines. |
| MalwareBFG Agonizer | BFG Agonizer uses elevated privileges to call |
| MalwareBlack Basta | Black Basta has used `ShellExecuteA` to shut down and restart the victim system. |
| MalwareCanisterWorm | CanisterWorm has forced the target system to reboot after file deletion. |
| MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can reboot or shutdown the targeted system or logoff the current user. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries forced victim devices to reboot to finalize destruction of impacted systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.