{"id":"T1014","name":"Rootkit","url":"https://attack.mitre.org/techniques/T1014","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0377","stix_id":"x-mitre-detection-strategy--00a4e92b-8164-4342-a71c-013ecc777ad0","name":"Detection of Kernel/User-Level Rootkit Behavior Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0377","analytics":[{"id":"AN1061","stix_id":"x-mitre-analytic--03f2259d-45c2-4422-83ad-58955f89350c","name":"Analytic 1061","description":"Unauthorized or anomalous loading of kernel-mode drivers or DLLs, concealed services, or abnormal modification of boot components indicative of rootkit activity.","url":"https://attack.mitre.org/detectionstrategies/DET0377#AN1061","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=6","data_component":"DC0079","data_component_name":"Driver Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:System","channel":"EventCode=7045","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"wineventlog-system"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"DriverSignatureStatus","description":"Signed vs unsigned drivers; many environments restrict unsigned drivers, but some legacy systems allow them."},{"field":"TargetDirectory","description":"Suspicious driver or DLL drop locations, e.g., \\System32\\Drivers\\ or \\Temp\\"},{"field":"UserContext","description":"Rootkit installation via admin or SYSTEM account."}],"live":true,"detection_strategies":["DET0377"],"techniques":["T1014"]},{"id":"AN1062","stix_id":"x-mitre-analytic--62cf396f-01d6-4ab0-a3f5-bf75d90c2c40","name":"Analytic 1062","description":"Abnormal loading of kernel modules, direct tampering with /dev, /proc, or LD_PRELOAD behaviors hiding processes or files.","url":"https://attack.mitre.org/detectionstrategies/DET0377#AN1062","platforms":["Linux"],"log_source_references":[{"name":"auditd:EXECVE","channel":"None","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-execve"},{"name":"linux:osquery","channel":"file_events","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"linux-osquery"},{"name":"linux:syslog","channel":"kmod","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"MonitoredDirectories","description":"Directories where kernel modules or tampering could be staged (e.g., /lib/modules/)."},{"field":"ModuleNamePattern","description":"Regex or heuristic match to anomalous module names (e.g., suspicious entropy or gibberish)."},{"field":"LD_PRELOAD","description":"Monitor presence of suspicious preload values that mask processes or files."}],"live":true,"detection_strategies":["DET0377"],"techniques":["T1014"]},{"id":"AN1063","stix_id":"x-mitre-analytic--0248d3dc-266e-45c3-89e4-4865f9174cfd","name":"Analytic 1063","description":"Execution of unsigned kernel extensions (KEXTs), tampering with LaunchDaemons, or userspace hooks into system libraries.","url":"https://attack.mitre.org/detectionstrategies/DET0377#AN1063","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"subsystem=com.apple.kextd","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"launch_daemons","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"macos-osquery"},{"name":"fs:fsevents","channel":"Extensions","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"fs-fsevents"}],"mutable_elements":[{"field":"KextSignatureStatus","description":"Allowable level of unsigned/3rd-party kernel extensions varies by organization."},{"field":"KextLoadOrigin","description":"Detect whether the extension was loaded by an untrusted process or non-root user."},{"field":"AnomalousLaunchAgent","description":"Detection tuned based on deviation from known/approved LaunchDaemon plist files."}],"live":true,"detection_strategies":["DET0377"],"techniques":["T1014"]}],"live":true,"version":"1.0","techniques":["T1014"]}],"sigma_rules":[{"id":"22236d75-d5a0-4287-bf06-c93b1770860f","title":"Triple Cross eBPF Rootkit Install Commands","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-07-05","modified":null,"description":"Detects default install commands of the Triple Cross eBPF rootkit based on the \"deployer.sh\" script","references":["https://github.com/h3xduck/TripleCross/blob/1f1c3e0958af8ad9f6ebe10ab442e75de33e91de/apps/deployer.sh"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.stealth","attack.t1014"],"path":"rules/linux/process_creation/proc_creation_lnx_triple_cross_rootkit_install.yml","techniques":["T1014"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}