Rootkit
Description
Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information. (Citation: Symantec Windows Rootkits) Rootkits or rootkit enabling functionality may reside at the user or kernel level in the operating system or lower, to include a hypervisor or [System Firmware](https://attack.mitre.org/techniques/T1542/001). (Citation: Wikipedia Rootkit) Rootkits have been seen for Windows, Linux, and Mac OS X systems. (Citation: CrowdStrike Linux Rootkit) (Citation: BlackHat Mac OSX Rootkit) Rootkits that reside or modify boot sectors are known as [Bootkit](https://attack.mitre.org/techniques/T1542/003)s and specifically target the boot process of the operating system.
Mapped SPARTA techniques
2 techniques
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Countered by 18 in MITRE D3FEND (Defensive Techniques)
- D3-AVEAsset Vulnerability Enumeration
- D3-CFContent Filtering
- D3-CMContent Modification
- D3-CQContent Quarantine
- D3-DFDecoy File
- D3-FAFile Analysis
- D3-FBAFirmware Behavior Analysis
- D3-FEFile Encryption
- D3-FEMCFirmware Embedded Monitoring Code
- D3-FEVFile Eviction
- D3-FIMFile Integrity Monitoring
- D3-FVFirmware Verification
- D3-LFPLocal File Permissions
- D3-RFRestore File
- D3-RFAMRemote File Access Mediation
- D3-RSRestore Software
- D3-SUSoftware Update
- D3-SWISoftware Inventory
Cite as SafeMode Space, mitre-attack-enterprise T1014.