T1529 System Shutdown/Reboot
High-Level Description
Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems. Operating systems may contain commands to initiate a shutdown/reboot of a machine or network device. In some cases, these commands may also be used to initiate a shutdown/reboot of a remote computer or network device via Network Device CLI (e.g. reload). They may also include shutdown/reboot of a virtual machine via hypervisor / cloud consoles or command line tools.
Shutting down or rebooting systems may disrupt access to computer resources for legitimate users while also impeding incident response/recovery.
Adversaries may also use Windows API functions, such as InitializeSystemShutdownExW or ExitWindowsEx, to force a system to shut down or reboot. Alternatively, the NtRaiseHardErroror ZwRaiseHardError Windows API functions with the ResponseOption parameter set to OptionShutdownSystem may deliver a “blue screen of death” (BSOD) to a system. In order to leverage these API functions, an adversary may need to acquire SeShutdownPrivilege (e.g., via Access Token Manipulation).
In some cases, the system may not be able to boot again.
Adversaries may attempt to shutdown/reboot a system after impacting it in other ways, such as Disk Structure Wipe or Inhibit System Recovery, to hasten the intended effects on system availability.
Kill Chain Phase
- Impact (TA0040)
Platforms: ESXi, Linux, macOS, Network Devices, Windows
What to Check
- Identify if System Shutdown/Reboot technique is applicable to target environment
- Check ESXi systems for indicators of System Shutdown/Reboot
- Check Linux systems for indicators of System Shutdown/Reboot
- Check macOS systems for indicators of System Shutdown/Reboot
- Assess detection coverage (1 detection strategies)
How to Test
Atomic Red Team Tests
The following tests are from Atomic Red Team and provide actionable ways to test this technique:
Atomic Test 1: Shutdown System - Windows
This test shuts down a Windows system.
Supported Platforms: windows Elevation Required: Yes
shutdown /s /t #{timeout}
Atomic Test 2: Restart System - Windows
This test restarts a Windows system.
Supported Platforms: windows Elevation Required: Yes
shutdown /r /t #{timeout}
Atomic Test 3: Restart System via shutdown - FreeBSD/macOS/Linux
This test restarts a FreeBSD/macOS/Linux system.
Supported Platforms: linux, macos Elevation Required: Yes
shutdown -r #{timeout}
Atomic Test 4: Shutdown System via shutdown - FreeBSD/macOS/Linux
This test shuts down a FreeBSD/macOS/Linux system using a halt.
Supported Platforms: linux, macos Elevation Required: Yes
shutdown -h #{timeout}
Atomic Test 5: Restart System via reboot - FreeBSD/macOS/Linux
This test restarts a FreeBSD/macOS/Linux system via reboot.
Supported Platforms: linux, macos Elevation Required: Yes
reboot
Manual Testing
If Atomic Red Team tests are not applicable, manually verify the technique by:
Identify Attack Surface: Determine if the target environment is susceptible to System Shutdown/Reboot by examining the target platforms (ESXi, Linux, macOS).
Assess Existing Defenses: Review whether mitigations for T1529 are in place. If defenses are absent or misconfigured, this technique may be exploitable.
Execute Test: Use tools and methods described in the MITRE ATT&CK page and external references below.
Remediation Guide
No specific mitigations documented for this technique.
Detection
Multi-Platform Shutdown or Reboot Detection via Execution and Host Status Events
Risk Assessment
| Finding | Severity | Impact |
|---|---|---|
| System Shutdown/Reboot technique applicable | High | Impact |
CWE Categories
| CWE ID | Title |
|---|---|
| CWE-400 | Uncontrolled Resource Consumption |