Windows Suspicious Shutdown or Reboot via shutdown.exe Command-Line

Flags shutdown.exe executions that include reboot (/r) or shutdown (/s) switches in the command line.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-01-01
Updated
2026-07-30

ATT&CK techniques

Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule flags process creation events where the executable is shutdown.exe and the command line contains either /r or /s switches. Attackers may use these switches to disrupt availability, interfere with incident response timing, or trigger system restarts. The detection relies on Windows process creation telemetry capturing the process image path and full command line arguments.

Related detections7 linkedT1529 — drag to rearrange
Linux auditd: Detect writes to /proc/sysrq-trigger or sysrq-related config for Magic SysRq abuse
Linux Process Creation: ESXi esxcli VM kill via vm process kill flags
Windows Suspicious Use of shutdown.exe to Log Off a User
macOS Shutdown/Reboot Command Execution via /shutdown, /reboot, or /halt Paths
Linux auditd: Shutdown, reboot, halt, poweroff or init-triggered system reboot
Windows PowerShell: Silence EmpireDNSAgent script matches DNS tunnel and remote shutdown/restart activity
Cisco AAA commands: shutdown or config-register changes to boot into alternate modes
Windows Suspicious Shutdown or Reboot via shutdown.exe Command-Line
Pivot detection · T1529 · 7 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.