FORENSIA

ATT&CK · T1529

System Shutdown/Reboot

Tactics: impact

About

Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems. Operating systems may contain commands to initiate a shutdown/reboot of a machine or network device. In some cases, these commands may also be used to initiate a shutdown/reboot of a remote computer or network device via Network Device CLI (e.g. <code>reload</code>). They may also include shutdown/reboot of a virtual machine via hypervisor / cloud consoles or command line tools. Shutting down or rebooting systems may disrupt access to computer resources for legitimate users while also impeding incident response/recovery. Adversaries may also use Windows API functions, such as `InitializeSystemShutdownExW` or `ExitWindowsEx`, to force a system to shut down or reboot. Alternatively, the `NtRaiseHardError`or `ZwRaiseHardError` Windows API functions with the `ResponseOption` parameter set to `OptionShutdownSystem` may deliver a “blue screen of death” (BSOD) to a system. In order to leverage these API functions, an adversary may need to acquire `SeShutdownPrivilege` (e.g., via Access Token Manipulation). In some cases, the system may not be able to boot again. Adversaries may attempt to shutdown/reboot a system after impacting it in other ways, such as Disk Structure Wipe or Inhibit System Recovery, to hasten the intended effects on system availability.

Platforms: ESXi, Linux, macOS, Network Devices, WindowsMITRE ATT&CK ↗

Used by actors

4 known groups

Software

25 malware/tools implement this

ShamoonRemcosOlympic DestroyerNotPetyaLockerGogaMazeLookBackKillDiskWhisperGateHermeticWiperDCSrvAvosLockerBlack BastaDarkGateAcidRainApostleMultiLayer WiperBFG AgonizerCHIMNEYSWEEPLatrodectusAcidPourShrinkLockerXLoaderQilinDynoWiper

Corpus indicators tagged with this technique

54 indicators in the corpus carry T1529.

IndicatorTypeFamilySevSrc
1e0f4cd09aa4464179933769b5009251hashransomware801
a88daa62751c212b7579a57f1f4ae8f8hashransomware801
7a311b584497e8133cd85950fec6132904dd5b02388a9feed3f5e057fb891d09hashransomware801
e00293ce0eb534874efd615ae590cf6aa3858ba4hashransomware801
d6aaed67606d6dab0f652c755d3d363025f60adbhashransomware801
0b33a1a23b044beb5c9a63aafd35595chashransomware801
00ff099e3cf7b548a7a0260cde8ac2f24a746da2hashransomware801
f4ae5b89db5a6a36dbd98287ab7c860ahashransomware801
36d968425629b10f38be17787f8afe4b8afa131ehashransomware801
30b49ae2f685d4403d3013410f80c2e2hashransomware801
5f5bf7fc7a9ac89ce0bbb07bd1160078hashransomware801
68225c5613afe2174ed46e074147676b0f9a3915hashransomware801
de1a114a2c5552387a1bbb61501bf129hashransomware801
7b885b446bbd9b450146c88f84c64f30hashransomware801
716e39bbc93fd4b394d9e6ef7c29aef1adc7dcb5hashransomware801
83c6c1bb37c9071e569aa4b247e54ab763bbf5dahashransomware801
bd79aec521aa9f0cec374d57692b540b7b5a6ea8hashransomware801
d875d7e99f45c87e667dbebb8d8596182bdb94dfhashransomware801
ebddc99a00bd7a5dcaf7b73349309d970e5c69b8hashransomware801
8468cb5888fb383d25f9144c2b2f61c414cea3f8hashransomware803
408dd6ade80f2ebbc2e5470a1fb506f1hashransomware801
05e9d6d239ea29f0427b02a9bc903be7hashransomware801
0a454a07e071971832985701bc6e9164hashransomware801
0f9cd505df07e4ebfff3fe61b689e527hashransomware801
124b943f6e82135b4d680df111ce121a200606dchashransomware801
143cb70aede3ba09ae54e1da55c69f0129991f48hashransomware801
1cc9ae55b1856e4e9796c73f94c2e683hashransomware801
23a468d7277902384875d4167a81164bc2bf6e72hashransomware801
4609cbac6772a6c61fcf2745cd3b4362hashransomware801
4c82fbafef9bab484a2fbe23e4ec8aac06e8e296d6c9e496f4a589f97fd4ab71hashransomware801

Showing the top 30 by severity of 54.