T1529 System Shutdown/Reboot — ATT&CK Technique
Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems. Operating systems may contain commands to initiate a shutdown/reboot of a machine or network device. In some cases, these commands may also be used to initiate a shutdown/reboot of a remote computer or network device via Network Device CLI (e.g. reload). They may also include shutdown/reboot of a virtual machine via hypervisor / cloud consoles or command line tools. Shutting down or rebooting systems may disrupt access to computer resources for legitimate users while also impeding incident response/recovery. Adversaries may also use Windows API functions, such as `InitializeSystemShutdownExW` or `ExitWindowsEx`, to force a system to shut down or reboot. Alternatively, the `NtRaiseHardError`or `ZwRaiseHardError` Windows API functions with the `ResponseOption` parameter set to `OptionShutdownSystem` may deliver a “blue screen of death” (BSOD) to a system. In order to leverage these API functions, an adversary may need to acquire `SeShutdownPrivilege` (e.g., via Access Token Manipulation). In some cases, the system may not be able to boot again. Adversaries may attempt to shutdown/reboot a system after impacting it in other ways, such as Disk Structure Wipe or Inhibit System Recovery, to hasten the intended effects on system availability.
Detection coverage (16)
- System Shutdown/Reboot - Linux informational
- ESXi VM Kill Via ESXCLI medium
- System Shutdown/Reboot - MacOs informational
- Cisco Denial of Service medium
- Potential Abuse of Linux Magic System Request Key medium
- Silence.EDA Detection critical
- Suspicious Execution of Shutdown to Log Out medium
- Suspicious Execution of Shutdown medium
- ESXi Bulk VM Termination
- Microsoft Intune Manual Device Management
- Linux Magic SysRq Key Abuse
- Linux System Reboot Via System Request Key
- Windows Common Abused Cmd Shell Risk Behavior
- Windows System LogOff Commandline
- Windows System Reboot CommandLine
- Windows System Shutdown CommandLine
Malware using this technique
- AcidRain
- DCSrv
- DynoWiper
- BFG Agonizer
- Qilin
- MultiLayer Wiper
- AcidPour
- LockerGoga
- Olympic Destroyer
- Maze
- LookBack
- Apostle
- KillDisk
- WhisperGate
- XLoader
- ShrinkLocker
- NotPetya
- Latrodectus
- CHIMNEYSWEEP
- DarkGate
- Black Basta
- Shamoon
- Remcos
- HermeticWiper
- AvosLocker