Anti-Forensics
Account Misuse
Clear Browser Artifacts
Clear Email Artifacts
Code Contribution Obfuscation and Misrepresentation
Decrease Privileges
Delayed Execution Triggers
Delete User Account
Deletion of Volume Shadow Copy
Disable Logging
Disk Wiping
File Deletion
File Encryption
Hide Artifacts
Hiding or Destroying Command History
Log Deletion
Log Modification
Message Deletion
Message Modification
Modify Windows Registry
Native Application Misuse
Network Obfuscation
Physical Destruction of Storage Media
Physical Removal of Disk Storage
Rootkit
Stalling
Steganography
System Shutdown
System Time Modification
Timestomping
Tripwires
Uninstalling Software
Virtualization
- ID: AF036
- Created: 19th July 2026
- Updated: 19th July 2026
- MITRE ATT&CK®: T1014
- Contributor: The ITM Team
Rootkit
A subject deploys or uses rootkit functionality to conceal programs, files, processes, network connections, services, drivers, accounts, or other system components from security monitoring and subsequent investigation.
Rootkits manipulate or intercept operating system functions responsible for reporting system activity, causing affected components to be omitted, altered, or misrepresented when reviewed through conventional administrative or forensic tools. Rootkit functionality may operate within user space, the operating system kernel, a hypervisor, or system firmware.
Preventions (5)
Detections (7)
MITRE ATT&CK® Mapping (1)
ATT&CK Enterprise Matrix Version 19.1