Windows System Shutdown/Reboot (Normalized Process Events)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This detection uses Normalized Process Events to detect System Shutdown/Reboot (MITRE Technique: T1529)

Attribute Value
Type Hunting Query
Solution GitHub Only
ID 614a59c5-2dae-4430-bb16-951a28a5f05f
Tactics Impact
Techniques T1529
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries