Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1014

T1014Rootkit

T1014 — Rootkit is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 11 detection use cases covering it and 6 threat-intel articles citing it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
11Use cases
6Articles
0Sub-techniques
1Tactic

Use cases covering this technique (11)

Linux Auditd Kernel Module Enumeration ESCU actions · hunting P Linux Kernel Module Enumeration ESCU actions · hunting P Linux Medusa Rootkit ESCU actions · alerting P Windows Driver Load Non-Standard Path ESCU actions · alerting P Windows Drivers Loaded by Signature ESCU actions · hunting P [LLM] CoolClient signed kernel rootkit msagent.sys dropped and registered as 'msagent' driver service Bespoke install · hunting DSΣPDDCS [LLM] CoolClient signed kernel rootkit: msagent.sys driver service install (Nanjing Ranyi cert) Bespoke install · alerting DSΣPDDCS [LLM] FudModule SYSTEM injection: msiexec.exe spawned by services.exe running as SYSTEM Bespoke exploit · alerting DSΣPDDCS [LLM] fast16 kernel driver (fast16.sys) drop / load — sabotage patching engine Bespoke install · alerting DSΣPDDCS [LLM] SprySOCKS WIN_DRV/WIN_PLUS backdoor binary by ESET SHA1 hash Bespoke install · hunting DSΣPDDCS [LLM] BYOVD: Genshin Impact mhyprot.sys driver dropped/loaded outside legitimate game install (Embargo evil-mhyprot-cli) Bespoke install · alerting DSΣP

Articles citing this technique (6)