Knowledge / malware acsc-glossary

Rootkit

Tooling that grabs high privilege and then hides. If you only look where it wants you to look, you will miss it.

A rootkit is used after a break-in to obtain high privilege and conceal that activity: files, processes, network sockets. The point is stealth, not a clever banner.

Host integrity, EDR with kernel visibility, and rebuild-from-known-good beat playing whack-a-file on a lying operating system. If you cannot trust the box, stop trusting the box.

Fact source: ASD's ACSC glossary.