Overview
User-mode rootkits hook API calls to hide files, processes and registry keys; bootkits and driver-level rootkits start earlier than the AV product and are far harder to remove.\nThe goal is persistence that survives reboots and ordinary admin scrutiny.\nWhen a rootkit is suspected, offline scanning or a rebuild from known-good media is the only reliable answer.
Indicators of Compromise
Signals that suggest this is present on a system.
- Signed drivers from unexpected publishers
- Process listings that disagree between two tools
- Files visible to one API but not another