Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1014
MITRE ATT&CK Technique

T1014: Rootkit

ShareXLinkedInRedditHN

Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information. (Citation: Symantec Windows Rootkits) Rootkits or rootkit enabling functionality may reside at the user or kernel level in the operating system or lower, to include a hypervisor or [System Firmware](https://attack.mitre.org/techniques/T1542/001). (Citation: Wikipedia Rootkit) Rootkits have been seen for Windows, Linux, and Mac OS X systems. (Citation: CrowdStrike Linux Rootkit) (Citation: BlackHat Mac OSX Rootkit) Rootkits that reside or modify boot sectors are known as [Bootkit](https://attack.mitre.org/techniques/T1542/003)s and specifically target the boot process of the operating system.

Tactics
Stealth
Platforms
Linux, macOS, Windows

▪Used by groups (6)

G0007APT28G0044Winnti GroupG0096APT41G0106RockeG0139TeamTNTG1048UNC3886

▪Software using this technique (24)

S0009HikitmalwareS0012PoisonIvymalwareS0022UroburosmalwareS0027ZeroaccessmalwareS0040HTRANtoolS0047Hacking Team UEFI RootkitmalwareS0135HIDEDRVmalwareS0221UmbreonmalwareS0377EburymalwareS0394HiddenWaspmalwareS0397LoJaxmalwareS0430Winnti for LinuxmalwareS0458RamsaymalwareS0468SkidmapmalwareS0484CarberpmalwareS0502DrovorubmalwareS0572Caterpillar WebShellmalwareS0601HildegardmalwareS0603StuxnetmalwareS0670WarzoneRATmalwareS1105COATHANGERmalwareS1186Line DancermalwareS1219REPTILEmalwareS1220MEDUSAmalware

▪Reference

T1014on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.