T1529 System Shutdown/Reboot Abuse via shutdown, wmic, PowerShell, rundll32

Detects the use of native Windows utilities such as shutdown.exe, wmic, powershell, and rundll32 to trigger an immediate system shutdown or restart, which may be indicative of unauthorized system disruption or malicious activity.