Rootkit
Definition
Malware designed to hide its own presence by subverting the operating system's reporting functions. User-mode rootkits hook API calls; kernel-mode rootkits modify kernel data structures. Detection requires analysis from outside the infected OS, typically via bootable forensic media or hypervisor-based inspection.
- Function
- Hides its own presence by subverting OS reporting functions
- User-mode technique
- Hooks API calls
- Kernel-mode technique
- Modifies kernel data structures
- Detection approach
- Analysis from outside the infected OS (bootable media or hypervisor-based)
Common questions
Why can't a rootkit reliably be detected by running antivirus software on the infected system itself?+
A rootkit that hooks API calls or modifies kernel structures can intercept the very queries the antivirus tool makes to list files, processes, or registry keys, returning falsified results that hide its own presence from software running on the compromised OS.
What is the practical difference between a user-mode and kernel-mode rootkit for an investigator?+
A user-mode rootkit intercepts calls at the application layer and is generally easier to detect by examining raw kernel structures, while a kernel-mode rootkit operates at a privilege level that can subvert the kernel's own view of the system, requiring analysis from outside the OS entirely.
Why is booting from external forensic media effective against rootkit concealment?+
It bypasses the compromised operating system's kernel and API layer entirely, so the rootkit's hooks are never loaded or executed, letting the investigator read the disk's true file and process artifacts directly.
Related terms
- Command and Control (C2)
- The channel through which an attacker sends instructions to malware on a compromised host and receives data back. C2 channels range from...
- Dropper
- A malware component whose sole function is to deliver and install a secondary payload. The dropper itself may be a trojan, a...
- Payload
- The action the malware performs once active: data encryption (ransomware), credential theft (banking trojan), resource hijacking (cryptominer), or system destruction (wiper). The...
- Persistence Mechanism
- The technique malware uses to survive a reboot or user logout. Common methods include registry run keys, scheduled tasks, Windows services, cron...
- Propagation Mechanism
- The method by which malware copies itself to new hosts. Viruses attach to host files; worms exploit network services autonomously; trojans rely...