1200KM / detection
T1547.006 Kernel Modules and Extensions — Detection Rules
Detection workspace for T1547.006 Kernel Modules and Extensions: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Loading of Kernel Module via Insmod · test · high · {"product":"linux","service":"auditd"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0450 Detection Strategy for Kernel Modules and Extensions Autostart Execution
AN1243 Analytic 1243
Monitor kernel module load/unload activity via modprobe, insmod, rmmod, or direct manipulation of /lib/modules. Correlate with installation of kernel headers, compilation commands, or downloads of .ko files. Detect anomalies in unsigned module loading or repeated module load attempts under non-root users.
AN1244 Analytic 1244
Detect user-initiated kextload commands or modifications to /Library/Extensions. Correlate with changes to KextPolicy database or unauthorized developer signing identities. Alert on attempts to disable SIP or load legacy extensions from unsigned sources.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1547.006 simulation workspace
- Command Execution · DC0064
- File Creation · DC0039
- File Modification · DC0061
- Kernel Module Load · DC0031
- Process Creation · DC0032
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.