// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE PUB-ENTDTG 0600Z
ColdReconTechniquesT1014
Technique T1014

Rootkit

CLEARED FOR PUBLIC RELEASE · OPEN-SOURCE INTELLIGENCE
Rootkit (T1014) — a Defense Evasion technique, observed in public incident reporting.
MITRE ATT&CKT1014
TacticDefense Evasion
Incidents on file10

Detection & mitigation

Monitor for unusual syscall patterns (e.g., indirect syscalls) and hidden processes using kernel-level telemetry. Deploy EDR with kernel-mode visibility and behavioral detection to identify rootkit activity and HVNC sessions.

Track this in real time.

ColdRecon watches the public signal so you don't have to — a daily brief and a live detection-coverage desk. Request clearance.

Request Clearance →