Windows Suspicious Use of shutdown.exe to Log Off a User

Flags Windows executions of shutdown.exe with /l to log a user off.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-10-01
Updated
2026-07-30

ATT&CK techniques

Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule flags process creations where shutdown.exe is executed with the /l argument, indicating an interactive logoff action. Attackers may use this to disrupt sessions or interfere with user access while attempting to cover activity. The detection relies on Windows process creation telemetry, matching the image path ending in \shutdown.exe and a command-line substring containing /l.

Related detections7 linkedT1529 — drag to rearrange
Linux auditd: Detect writes to /proc/sysrq-trigger or sysrq-related config for Magic SysRq abuse
Linux Process Creation: ESXi esxcli VM kill via vm process kill flags
Windows Suspicious Shutdown or Reboot via shutdown.exe Command-Line
macOS Shutdown/Reboot Command Execution via /shutdown, /reboot, or /halt Paths
Linux auditd: Shutdown, reboot, halt, poweroff or init-triggered system reboot
Windows PowerShell: Silence EmpireDNSAgent script matches DNS tunnel and remote shutdown/restart activity
Cisco AAA commands: shutdown or config-register changes to boot into alternate modes
Windows Suspicious Use of shutdown.exe to Log Off a User
Pivot detection · T1529 · 7 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.