macOS Shutdown/Reboot Command Execution via /shutdown, /reboot, or /halt Paths

Flags macOS process executions ending with shutdown, reboot, or halt indicating possible host power disruption.

FreeReviewedSigma · Informational · v2
Product
macos
Category
process_creation
Author
Igor Fits, Mikhail Larin, oscd.community (SigmaHQ), DRL 1.1
Published
2020-10-19
Updated
2026-07-31

ATT&CK techniques

Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule flags process executions where the process image path ends with /shutdown, /reboot, or /halt on macOS. Attackers can use system restarts or shutdowns to disrupt access to a target host and hinder incident response, or as part of broader impact activities. Telemetry relies on process creation data that includes the executing image path.

Related detections7 linkedT1529 — drag to rearrange
Linux auditd: Detect writes to /proc/sysrq-trigger or sysrq-related config for Magic SysRq abuse
Linux Process Creation: ESXi esxcli VM kill via vm process kill flags
Windows Suspicious Use of shutdown.exe to Log Off a User
Windows Suspicious Shutdown or Reboot via shutdown.exe Command-Line
Linux auditd: Shutdown, reboot, halt, poweroff or init-triggered system reboot
Windows PowerShell: Silence EmpireDNSAgent script matches DNS tunnel and remote shutdown/restart activity
Cisco AAA commands: shutdown or config-register changes to boot into alternate modes
macOS Shutdown/Reboot Command Execution via /shutdown, /reboot, or /halt Paths
Pivot detection · T1529 · 7 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.