• Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right

DETECTION OVERVIEW

New Remote System Shutdown Attempt

Risk Factors

On a default Windows configuration, it is relatively easy to shut down or restart a device remotely. But a remote device shut down can be detected easily. A malicious shutdown can destroy data or cause a denial-of-service (DoS).

The system might change the risk score for this detection.

Kill Chain

Actions on Objective

Risk Score

56

Next in Actions on Objective: New User Creation Attempt

Attack Background

An attacker can have many reasons to shut down or restart a device from a remote system. An attacker might want to destroy the contents of system memory, initiate changes that are triggered by a reboot, or disable the device. One approach for remotely shut down a device is to send Microsoft remote procedure call (MS-RPC) requests to an interface on the victim device, such as WsdrInitiateShutdown, RpcWinStationShutdownSystem, BaseInitiateShutdownEx, or BaseInitiateSystemShutdown.

Mitigation Options

Investigate unusual system shutdowns to minimize potential damage

Limit the number of privileged users in your environment

Implement network segmentation and firewall policies to limit how devices can communicate and enforce security zones

Maintain off-site and up-to-date backup files that can restore critical data and systems

MITRE ATT&CK ID

What else can RevealX do for you?