Techniques › T1014
T1014 Rootkit
stealth — Linux, macOS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
3
analytics
1
Sigma rules tagged attack.t1014
0
KEV CVEs mapped here
<p>Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information.</p><p>Rootkits or rootkit enabling functionality may reside at the user or kernel level in the operating system or lower, to include a hypervisor or System Firmware. Rootkits have been seen for Windows, Linux, and Mac OS X systems.</p><p>Rootkits that reside or modify boot sectors are known as Bootkits and specifically target the boot process of the operating system.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0377 Detection of Kernel/User-Level Rootkit Behavior Across Platforms v1.0
AN1061 WindowsUnauthorized or anomalous loading of kernel-mode drivers or DLLs, concealed services, or abnormal modification of boot components indicative of rootkit activity.Tunable:
DriverSignatureStatusTargetDirectoryUserContextAN1062 LinuxAbnormal loading of kernel modules, direct tampering with /dev, /proc, or LD_PRELOAD behaviors hiding processes or files.Tunable:MonitoredDirectoriesModuleNamePatternLD_PRELOADAN1063 macOSExecution of unsigned kernel extensions (KEXTs), tampering with LaunchDaemons, or userspace hooks into system libraries.Tunable:KextSignatureStatusKextLoadOriginAnomalousLaunchAgent
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1014
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-07-05 · logsource: product=linux category=process_creation · 22236d75-d5a0-4287-bf06-c93b1770860f
Detects default install commands of the Triple Cross eBPF rootkit based on the "deployer.sh" script