// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE PUB-ENTDTG 0600Z
ColdReconTechniquesT1014
Technique T1014

Rootkit

CLEARED FOR PUBLIC RELEASE · OPEN-SOURCE INTELLIGENCE
Rootkit (T1014) — a Defense Evasion technique, observed in public incident reporting.
MITRE ATT&CKT1014
TacticDefense Evasion
Incidents on file9

Detection & mitigation

Monitor for loading of unsigned or unusual kernel drivers using Sysmon Event ID 6 and driver block rules. Enable Microsoft Defender for Endpoint's attack surface reduction rules to block known vulnerable drivers and use memory integrity (HVCI) to prevent unsigned driver loading.

Track this in real time.

ColdRecon watches the public signal so you don't have to — a daily brief and a live detection-coverage desk. Request clearance.

Request Clearance →