Skip to content
CIM-072 Cyber Incidents & Offender Methods

What is a rootkit?

A rootkit is software or code designed to conceal activity or maintain privileged access by operating at a deep level of the system.

Avoid the dangerous assumption

The dangerous assumption is that any difficult-to-remove malware is a rootkit.

It is not.

A rootkit may alter or interfere with the operating system, startup process, drivers, firmware or system tools so that files, processes, connections or accounts are hidden.

This can affect the reliability of normal examination.

Investigators should consider specialist support where a rootkit is suspected because the compromised system may not accurately report its own state.

Evidence may include:

  • unexpected drivers
  • modified system components
  • hidden processes
  • integrity-check failures
  • boot changes
  • firmware anomalies
  • security-tool tampering
  • specialist forensic findings.

The presence of rootkit-like artefacts does not automatically prove malicious intent. Some security, management or specialist software operates at similarly privileged levels.

Likewise, the absence of visible malware does not exclude a rootkit if the mechanism is designed to hide itself.

Do not rely solely on scans conducted from within the suspected system.

Preserve the system state and consider trusted external examination methods.

A rootkit may provide persistence or concealment without evidence that every available access function was used.

Rootkit suspicion should be reported cautiously. Describe the integrity concerns and specialist findings rather than using the label as a substitute for explaining what was hidden, altered or made unreliable.

Operational takeaway

Treat suspected rootkit activity as a reliability problem for the affected system and use trusted specialist examination before accepting its own records at face value.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.