1200KM / simulation
T1529 System Shutdown/Reboot — Attack Simulation
Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems. Operating systems may contain commands to initiate a shutdown/reboot of a machine or network device. In some cases, these commands may also be used to initiate a shutdown/reboot of a remote computer or network device via Network Device CLI (e.g. reload). They may also include shutdown/reboot of a virtual machine via hypervisor / cloud…
Technique description
Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems. Operating systems may contain commands to initiate a shutdown/reboot of a machine or network device. In some cases, these commands may also be used to initiate a shutdown/reboot of a remote computer or network device via Network Device CLI (e.g. reload). They may also include shutdown/reboot of a virtual machine via hypervisor / cloud…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- ESXi - Avoslocker enumerates VMs and forcefully kills VMs
Procedure 189f7d6e-9442-4160-9bc3-5e4104d93ece; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Logoff System - Windows
Procedure 3d8c25b5-7ff5-4c9d-b21f-85ebd06654a4; elevation required; cleanup not declared. Not executed or individually validated.
- Restart System via `reboot` - FreeBSD/macOS/Linux
Procedure 47d0b042-a918-40ab-8cf9-150ffe919027; elevation required; cleanup not declared. Not executed or individually validated.
- Shutdown System via `shutdown` - FreeBSD/macOS/Linux
Procedure 4963a81e-a3ad-4f02-adda-812343b351de; elevation required; cleanup not declared. Not executed or individually validated.
- Reboot System via `poweroff` - FreeBSD
Procedure 5a282e50-86ff-438d-8cef-8ae01c9e62e1; elevation required; cleanup not declared. Not executed or individually validated.
- Reboot System via `poweroff` - Linux
Procedure 61303105-ff60-427b-999e-efb90b314e41; elevation required; cleanup not declared. Not executed or individually validated.
- ESXi - vim-cmd Used to Power Off VMs
Procedure 622cc1a0-45e7-428c-aed7-c96dd605fbe6; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Restart System via `shutdown` - FreeBSD/macOS/Linux
Procedure 6326dbc4-444b-4c04-88f4-27e94d0327cb; elevation required; cleanup not declared. Not executed or individually validated.
- Shutdown System via `poweroff` - FreeBSD/Linux
Procedure 73a90cd2-48a2-4ac5-8594-2af35fa909fa; elevation required; cleanup not declared. Not executed or individually validated.
- Reboot System via `halt` - Linux
Procedure 78f92e14-f1e9-4446-b3e9-f1b921f2459e; elevation required; cleanup not declared. Not executed or individually validated.
- Reboot System via `halt` - FreeBSD
Procedure 7b1cee42-320f-4890-b056-d65c8b884ba5; elevation required; cleanup not declared. Not executed or individually validated.
- Shutdown System via `halt` - FreeBSD/Linux
Procedure 918f70ab-e1ef-49ff-bc57-b27021df84dd; elevation required; cleanup not declared. Not executed or individually validated.
- ESXi - Terminates VMs using pkill
Procedure 987c9b4d-a637-42db-b1cb-e9e242c3991b; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Shutdown System - Windows
Procedure ad254fa8-45c0-403b-8c77-e00b3d3e7a64; elevation required; cleanup not declared. Not executed or individually validated.
- Abuse of Linux Magic System Request Key for Reboot
Procedure d2a1f4bc-a064-4223-8281-a086dce5423c; elevation required; cleanup not declared. Not executed or individually validated.
- Restart System - Windows
Procedure f4648f0d-bf78-483c-bafc-3ec99cd1c302; elevation required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.