What is a rootkit?¶
A rootkit is a set of techniques or software designed to conceal activity while retaining privileged access to a system. Its importance is not just what it may hide: a sufficiently privileged rootkit can also make the affected system's own reports incomplete or misleading.
The term describes a purpose rather than one fixed program. Rootkit behaviour can operate in user processes, the operating-system kernel, the boot process or, in rarer cases, device firmware. The deeper it operates, the more effectively it may intercept requests and suppress the files, processes, accounts or network activity that ordinary tools would otherwise reveal.
Why normal inspection may not be enough¶
Many examination tools ask the running operating system for information. A rootkit with the right privileges may alter the answer before it reaches the tool. A process list that looks clean therefore does not necessarily prove that no hidden process exists.
Useful indicators can include:
- unexpected or unsigned drivers and modified system components;
- differences between filesystem views obtained by independent methods;
- processes, modules or connections visible in memory but absent from normal listings;
- integrity-check failures or unexplained changes to boot configuration;
- security tools being disabled, redirected or returning inconsistent results; and
- persistence mechanisms linked to privileged or concealed code.
These are leads, not automatic proof. Security products, hardware-management tools and other legitimate privileged software can produce some of the same observations.
Building a reliable explanation¶
Where concealment is suspected, evidence obtained from outside the affected operating system carries particular value. That may include a forensic image examined on a trusted system, independently acquired memory, secure-boot or firmware records, and comparisons with known-good software.
The account, process or installer associated with a suspicious component should be connected to a timeline: when it arrived, how it gained privilege, what it concealed and what activity continued afterwards. Even a confirmed rootkit does not by itself identify the person who deployed it. Access may have passed through compromised accounts, automated malware or another intermediary.
Key takeaway
A rootkit is evidence of privileged concealment, but its presence, operation and human attribution must be established separately using evidence that does not rely solely on the potentially compromised system.