Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Impact/ T1529

T1529System Shutdown/Reboot

T1529 — System Shutdown/Reboot is a MITRE ATT&CK technique in the Impact tactic. Clankerusecase tracks 11 detection use cases covering it and 4 threat-intel articles citing it.

Impact
View on the matrix → Filter Detection Library MITRE official spec ↗
11Use cases
4Articles
0Sub-techniques
1Tactic

Use cases covering this technique (11)

ESXi Bulk VM Termination ESCU actions · alerting P Microsoft Intune Manual Device Management ESCU actions · hunting P Linux Magic SysRq Key Abuse ESCU actions · alerting P Linux System Reboot Via System Request Key ESCU actions · alerting P Windows Common Abused Cmd Shell Risk Behavior ESCU actions · alerting P Windows System LogOff Commandline ESCU actions · hunting P Windows System Reboot CommandLine ESCU actions · hunting P Windows System Shutdown CommandLine ESCU actions · hunting P [LLM] Tengu ELF-header corruption ('ELFOOD') of Linux reboot/shutdown utilities Bespoke install · hunting DSΣPCS [LLM] Host-root mount wiper: chroot /mnt/host reboot -f or rm -rf / --no-preserve-root Bespoke actions · alerting DSΣPDDCS [LLM] Shell rc files (.bashrc/.zshrc) modified by package-install process — s1ngularity persistence/shutdown Bespoke install · hunting DSΣPCS

Articles citing this technique (4)