Skip to content
System

System Event ID 6008: Unexpected shutdown

The previous system shutdown was unexpectedSystem event 6008 is logged at boot when the previous shutdown was unexpected, with the approximate local time the system went down. Pairs with Kernel-Power 41.
6008
Event ID
6008
Channel
System
Provider
EventLog
Log file
System.evtx
Category
System
Default logging
Logged by default

What event 6008 means

Event 6008 is written by the Event Log service at startup when it finds that the previous session did not end with a clean shutdown. The message gives the time and date of the unexpected shutdown, in the local time zone and the system's date format.

That time is an approximation: it comes from a periodic "last alive" timestamp the system keeps while running, so the real stop may be slightly later than reported. It is still the best estimate of when the machine died, which 41 (Kernel-Power, logged at the same boot) does not provide.

6008 bounds a period with no logging. Use it to explain gaps in other logs and to check whether a crash or power cut coincides with suspicious activity.

When it is logged

Audit policy / configuration

Always logged to the System log at the first boot after an unclean shutdown.

The data is a set of unnamed insertion strings; this viewer shows them joined in Data1. The date may contain invisible left-to-right marks from locale formatting.

Key fields

FieldWhat it tells you
Data1Insertion strings; the first is the local time and the second the date of the unexpected shutdown (e.g. 3:45:12 PM, 4/4/2020).

Common benign sources

  • Power loss, battery exhaustion, blue screens and hard resets.
  • Virtual machines killed or reset from the hypervisor.

What attackers do that produces it

  • Crashes caused by kernel exploits or vulnerable drivers loaded to tamper with security tools.
  • Deliberate hard resets to interrupt logging or response.

Investigation tips

  • Correlate with 41 at the same boot to read the bugcheck code, if any.
  • Look at the last records before the reported time and at driver or service installs (7045) just before.
  • Convert the local time to UTC using the host time zone (see 6013) before building the timeline.

MITRE ATT&CK techniques

TechniqueTactics
T1529 System Shutdown/RebootImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading