CLEARED FOR PUBLIC RELEASE · OPEN-SOURCE INTELLIGENCE
Rootkit (T1014) — a Defense Evasion technique, observed in public incident reporting.
MITRE ATT&CKT1014
TacticDefense Evasion
Incidents on file10
Detection & mitigation
Monitor for unusual syscall patterns (e.g., indirect syscalls) and hidden processes using kernel-level telemetry. Deploy EDR with kernel-mode visibility and behavioral detection to identify rootkit activity and HVNC sessions.