Insider Threat Matrix™Insider Threat Matrix™
  • ID: AF036
  • Created: 19th July 2026
  • Updated: 19th July 2026
  • MITRE ATT&CK®: T1014
  • Contributor: The ITM Team

Rootkit

A subject deploys or uses rootkit functionality to conceal programs, files, processes, network connections, services, drivers, accounts, or other system components from security monitoring and subsequent investigation.

 

Rootkits manipulate or intercept operating system functions responsible for reporting system activity, causing affected components to be omitted, altered, or misrepresented when reviewed through conventional administrative or forensic tools. Rootkit functionality may operate within user space, the operating system kernel, a hypervisor, or system firmware.