Rootkit T1014

Tactic: Stealth

Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information.

Events covered

7 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 37 rules share fields, values, and exclusions.

Fields filtered most (40 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType26eq 19, in 7, ne 1exec, load_module, ProcessRollup2, exec_event, creation
host.os.type22eq 22
process_name18eq 12, in 5, starts_with 4bash, kernel, kmod, kworker, bpftool
event.type15eq 15start, change, creation
process.args9eq 6, in 5, starts_with 4, contains 2, wildcard 1.ko, link, --bytes, --clear, --decode
Image5is_not_null 2, ends_with 1, starts_with 1, wildcard 1./*, /boot/*, /dev/shm/, /dev/shm/*, /sudo
data_stream.dataset4eq 4system.syslog, fim.event
event.category4eq 4process, file, network
user.id4eq 3, ne 10, s-1-5-18
CommandLine3contains 2, in 1, wildcard 1 enp0s3 , filter , qdisc , */home/*/.ssh/*, *list*
ParentImage3is_not_null 2, starts_with 1./, /boot/, /dev/shm/
TargetFilename3wildcard 2, in 1*.backup_ld.so, *.boot.sh, *.logpam, /boot/efi/efi/*/grub.cfg, /boot/grub/grub.cfg
auditd.data.syscall3in 2, eq 1finit_module, init_module, kill
file.extension3eq 3dll, exe, ko, sys
message3eq 3bpf_probe_write_user, loading out-of-tree module taints kernel., module verification failed: signature and/or required...

Top indicator values (501 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
131078
EventTypeeq
load_module
66
EventTypeeq
exec
4576
EventTypeeq
creation
258
EventTypeeq
loaded-kernel-module
22
EventTypeeq
memfd_create
27
EventTypein
exec
5201
EventTypein
ProcessRollup2
4117
EventTypein
exec_event
4149
EventTypein
executed
498
EventTypein
process_started
483
EventTypein
start
4163
data_stream.dataseteq
system.syslog
35
process_nameeq
kernel
36
process_nameeq
kmod
34
process_namein
bash
3202
process_namein
csh
3159
process_namein
dash
3170
process_namein
fish
3163
process_namein
ksh
3163
process_namein
sh
3197
process_namein
tcsh
3156
process_namein
zsh
3196
process_namestarts_with
kworker
34
TargetFilenamewildcard
/etc/modprobe.d/*
22
TargetFilenamewildcard
/etc/modules
22
TargetFilenamewildcard
/etc/modules-load.d/*
22
TargetFilenamewildcard
/run/modules-load.d/*
22
TargetFilenamewildcard
/usr/lib/modprobe.d/*
22
TargetFilenamewildcard
/usr/lib/modules-load.d/*
22

Exclusions (353 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Imagestarts_with
/tmp/newroot/
3
Imagestarts_with
/snap/
2
ParentImagewildcard
/snap/lxd/*/sbin/lxd
2
file.extensionin
dpkg-remove
2
process_namein
umount
2
CommandLinecontains
/bin/ps
1
CommandLinecontains
/usr/bin/find
1
CommandLinecontains
/usr/bin/grep
1
CommandLinecontains
ds_agent
1
CommandLinecontains
gitlabrunner
1
CommandLinecontains
nagios
1
CommandLinecontains
omsagent
1
CommandLinecontains
pgrep
1
CommandLineeq
/opt/eset/efs/lib/oaeventd
1
CommandLineeq
/opt/eset/efs/sbin/startd
1

Rules under this technique

These vendors publish rules tagged with this technique.

Domain: Endpoint

Platform (all)

Sigma 2 rules

Elastic 29 rules

Splunk 5 rules

Panther 1 rule