BIOC Informational

Shutdown command issued

This behavior is often observed by malware attempting to force a machine shutdown after a period of time once file encryption has completed.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Tampering
Status:
Enabled
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: System Shutdown/Reboot (T1529)
Indicator:

Process action type = execution AND target process cmd = *shutdown.exe*

Preventable: yes