Insider Threat Matrix™

  • ID: DT016
  • Created: 30th May 2024
  • Updated: 14th June 2024
  • Platform: Windows
  • Contributor: The ITM Team

Windows System Shutdown, Event Logs

A subject may power off a system to prevent the contents of memory being read.

Event ID 41 documents when “The system has rebooted without cleanly shutting down first”.

Event ID 1074 documents when “The system has been shutdown properly by a user or process”.

This may represent an anti-forensics technique if there is no reasonable explanation for why the system was powered off.


ID Name Description
AF014System Shutdown

A subject may shutdown a system to clear volatile memory (RAM), preventing memory acquisition and analysis.