Technique
№ 017 · class: execution
Rootkit Installation
Technique of installing a rootkit to deeply hide presence on a system.
Term
description · examples · notesTechnique of installing a rootkit to deeply hide presence on a system.
Description
Can operate at user-space, kernel, or firmware (UEFI) level.
Kernel rootkits modify system calls to hide files and processes.
UEFI rootkits survive operating system reinstallation.
Requires previously obtained administrative or kernel privileges.
Examples
- LoJax UEFI rootkit found in APT28 operations
- Necurs rootkit for hiding botnet components
Notes
- Technique (how it is installed) for the rootkit threat.
Threats
used by 2Defenses
countered by 4How it is countered. Select one to open its page.