Rootkit
Tooling that grabs high privilege and then hides. If you only look where it wants you to look, you will miss it.
A rootkit is used after a break-in to obtain high privilege and conceal that activity: files, processes, network sockets. The point is stealth, not a clever banner.
Host integrity, EDR with kernel visibility, and rebuild-from-known-good beat playing whack-a-file on a lying operating system. If you cannot trust the box, stop trusting the box.
Fact source: ASD's ACSC glossary.
