System Shutdown/Reboot

T1529

Technique.View on attack.mitre.org

About this technique

Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems. Operating systems may contain commands to initiate a shutdown/reboot of a machine or network device. In some cases, these commands may also be used to initiate a shutdown/reboot of a remote computer or network device via Network Device CLI (e.g. reload). They may also include shutdown/reboot of a virtual machine via hypervisor / cloud consoles or command line tools.

Shutting down or rebooting systems may disrupt access to computer resources for legitimate users while also impeding incident response/recovery.

Adversaries may also use Windows API functions, such as `InitializeSystemShutdownExW` or `ExitWindowsEx`, to force a system to shut down or reboot. Alternatively, the `NtRaiseHardError`or `ZwRaiseHardError` Windows API functions with the `ResponseOption` parameter set to `OptionShutdownSystem` may deliver a “blue screen of death” (BSOD) to a system. In order to leverage these API functions, an adversary may need to acquire `SeShutdownPrivilege` (e.g., via Access Token Manipulation).
In some cases, the system may not be able to boot again.

Adversaries may attempt to shutdown/reboot a system after impacting it in other ways, such as Disk Structure Wipe or Inhibit System Recovery, to hasten the intended effects on system availability.

Detection rules16

Rules on DetectionCode tagged with T1529.

Sigma8

RuleLevelLog source
Silence.EDA Detectioncriticalwindows / ps_script
Cisco Denial of Servicemediumcisco / NULL
ESXi VM Kill Via ESXCLImediumlinux / process_creation
Potential Abuse of Linux Magic System Request Keymediumlinux / NULL
Suspicious Execution of Shutdownmediumwindows / process_creation
Suspicious Execution of Shutdown to Log Outmediumwindows / process_creation
System Shutdown/Reboot - Linuxinformationallinux / NULL
System Shutdown/Reboot - MacOsinformationalmacos / process_creation

Splunk8

RuleTypeRiskData source
ESXi Bulk VM TerminationTTPNULLVMWare ESXi Syslog
Linux Magic SysRq Key AbuseTTPNULLLinux Auditd Path, Linux Auditd Cwd
Linux System Reboot Via System Request KeyTTPNULLSysmon for Linux EventID 1
Microsoft Intune Manual Device ManagementHuntingNULLAzure Monitor Activity
Windows Common Abused Cmd Shell Risk BehaviorCorrelationNULL
Windows System LogOff CommandlineAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows System Reboot CommandLineHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows System Shutdown CommandLineAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups4

Software26

Show 2 more

Campaigns1

Procedure examples31

Groups4

Used byProcedure example
GroupAPT37

APT37 has used malware that will issue the command shutdown /r /t 1 to reboot a system after wiping its MBR.

GroupAPT38

APT38 has used a custom MBR wiper named BOOTWRECK, which will initiate a system reboot after wiping the victim's MBR.

GroupLazarus Group

Lazarus Group has rebooted systems after destroying files and wiping the MBR on infected systems.

GroupMedusa Group

Medusa Group has manually turned off and encrypted virtual machines.

Software26

Used byProcedure example
MalwareAcidPour

AcidPour includes functionality to reboot the victim system following wiping actions, similar to AcidRain.

MalwareAcidRain

AcidRain reboots the target system once the various wiping processes are complete.

MalwareApostle

Apostle reboots the victim machine following wiping and related activity.

MalwareAvosLocker

AvosLocker’s Linux variant has terminated ESXi virtual machines.

MalwareBFG Agonizer

BFG Agonizer uses elevated privileges to call NtRaiseHardError to induce a "blue screen of death" on infected systems, causing a system crash. Once shut down, the system is no longer bootable.

MalwareBlack Basta

Black Basta has used `ShellExecuteA` to shut down and restart the victim system.

MalwareCanisterWorm

CanisterWorm has forced the target system to reboot after file deletion.

MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can reboot or shutdown the targeted system or logoff the current user.

View all 26 software examples

Campaigns1

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries forced victim devices to reboot to finalize destruction of impacted systems.

References9

  1. CrowdStrike Blog Open source
    William Thomas, Adrian Liviu Arsene, Farid Hendi. (2022, February 25). CrowdStrike Falcon® Protects from New Wiper Malware Used in Ukraine Cyberattacks. Retrieved September 22, 2025.
  2. Microsoft Shutdown Oct 2017 Open source
    Microsoft. (2017, October 15). Shutdown. Retrieved October 4, 2019.
  3. NotMe-BSOD Open source
    lzcapp. (n.d.). Retrieved September 22, 2025.
  4. NtRaiseHardError Open source
    NtDoc. (n.d.). NtRaiseHardError - NtDoc. Retrieved September 22, 2025.
  5. SonicWall Open source
    SecurityNews. (2024, July 12). Disarming DarkGate: A Deep Dive into Thwarting the Latest DarkGate Variant. Retrieved September 22, 2025.
  6. Talos Nyetya June 2017 Open source
    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.
  7. Talos Olympic Destroyer 2018 Open source
    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.
  8. Unit42 Agrius 2023 Open source
    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.
  9. alert_TA18_106A Open source
    CISA. (2018, April 20). Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved February 14, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.