1200KM / simulation
T1014 Rootkit — Attack Simulation
Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information. Rootkits or rootkit enabling functionality may reside at the user or kernel level in the operating system or lower, to include a hypervisor or System…
Technique description
Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information. Rootkits or rootkit enabling functionality may reside at the user or kernel level in the operating system or lower, to include a hypervisor or System…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Loadable Kernel Module based Rootkit (Diamorphine)
Procedure 0b996469-48c6-46e2-8155-a17f8b6c2247; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- dynamic-linker based rootkit (libprocesshider)
Procedure 1338bf0c-fd0c-48c0-9e65-329f18e2c0d3; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Loadable Kernel Module based Rootkit
Procedure 75483ef8-f10f-444a-bf02-62eb0e48db6f; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Loadable Kernel Module based Rootkit
Procedure dfb50072-e45a-4c75-a17e-a484809c8553; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.