Skip to content
System

System Event ID 13: Operating system shutdown

The operating system is shutting down at system timeSystem event 13 (Kernel-General) is written on a clean shutdown with the exact stop time. No 13 before a boot means a crash or power loss.
13
Event ID
13
Channel
System
Provider
Microsoft-Windows-Kernel-General
Log file
System.evtx
Category
System
Default logging
Logged by default

What event 13 means

Event 13 is the kernel's last word before a clean shutdown or restart. StopTime gives the precise moment, and the record is usually one of the last in the System log for that session.

On its own it says little about why the system went down. The reason and the requester are in 1074 (User32), written a few seconds earlier, and 6006 (EventLog service stopped) appears around the same time. The next boot starts with 12.

The absence of a 13 is what matters most: if a boot (12) follows without a 13, the previous session ended abruptly — crash, power loss, hard reset — and Windows will log 41 and 6008 on the next start.

When it is logged

Audit policy / configuration

Always logged to the System log on a clean shutdown or restart.

Key fields

FieldWhat it tells you
StopTimeUTC time at which the kernel began the shutdown.

Common benign sources

  • Users and administrators shutting down or restarting the host.
  • Restarts scheduled by Windows Update or configuration management.

What attackers do that produces it

  • Attackers restarting a host to activate persistence or drivers, or shutting systems down as part of an impact phase (T1529).

Investigation tips

  • Look for 1074 just before the 13 to identify the requesting process, user and reason.
  • Measure the downtime until the next 12; long gaps on servers deserve an explanation.
  • A missing 13 between two boots points to a crash; check 41 and 6008.

MITRE ATT&CK techniques

TechniqueTactics
T1529 System Shutdown/RebootImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading