Linux auditd: Shutdown, reboot, halt, poweroff or init-triggered system reboot

Identifies Linux shutdown/reboot command execution patterns using auditd execve telemetry.

FreeReviewedSigma · Informational · v3
Product
linux
Service
auditd
Author
Igor Fits, oscd.community (SigmaHQ), DRL 1.1
Published
2020-10-15
Updated
2026-07-31

ATT&CK techniques

Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule flags command execution events where a process invokes system power state changes such as shutdown, reboot, halt, or poweroff, or where init/telinit is executed in specific argument positions. Such actions can be used to interrupt access to a system or to hinder analysis by forcing restarts or shutdowns. It relies on Linux auditd EXECVE telemetry to capture the executed program and its arguments.

Related detections7 linkedT1529 — drag to rearrange
Linux auditd: Detect writes to /proc/sysrq-trigger or sysrq-related config for Magic SysRq abuse
Linux Process Creation: ESXi esxcli VM kill via vm process kill flags
Windows Suspicious Use of shutdown.exe to Log Off a User
Windows Suspicious Shutdown or Reboot via shutdown.exe Command-Line
macOS Shutdown/Reboot Command Execution via /shutdown, /reboot, or /halt Paths
Windows PowerShell: Silence EmpireDNSAgent script matches DNS tunnel and remote shutdown/restart activity
Cisco AAA commands: shutdown or config-register changes to boot into alternate modes
Linux auditd: Shutdown, reboot, halt, poweroff or init-triggered system reboot
Pivot detection · T1529 · 7 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.