MITRE ATT&CK ICS
T0851

Rootkit

Description

Adversaries may deploy rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting and modifying operating-system API calls that supply system information. Rootkits or rootkit-enabling functionality may reside at the user or kernel level in the operating system, or lower. (Citation: Enterprise ATT&CK January 2018) Firmware rootkits that affect the operating system yield nearly full control of the system. While firmware rootkits are normally developed for the main processing board, they can also be developed for the I/O that is attached to an asset. Compromise of this firmware allows the modification of all of the process variables and functions the module engages in. This may result in commands being disregarded and false information being fed to the main device. By tampering with device processes, an adversary may inhibit its expected response functions and possibly enable [Impact](https://attack.mitre.org/tactics/TA0105).

Mapped SPARTA techniques

2 techniques

  • DE-0007Evasion via RootkitST0006
    addresses
    high

    T0851 'Rootkit' is the exact-title-and-scope ATT&CK ICS evasion-tactic technique; SPARTA DE-0007 'Evasion via Rootkit' is the same activity at cross-framework level. Tactic and activity align directly.

  • EX-0010.03RootkitST0004
    addresses
    moderate

    T0851 'Rootkit' is the exact-title-and-scope ATT&CK ICS technique for kernel/RTOS-resident concealment payloads; SPARTA EX-0010.03 covers spacecraft rootkits. Cross-tactic moderate (T0851 sits in evasion and inhibit-response-function while SPARTA EX-0010.03 is execution).

Cite as SafeMode Space, mitre-attack-ics T0851.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.