Malware
Rootkit
Rootkit
Stealth software that hides its presence and grants deep access to a system.
Fiche de sensibilisationPrête à diffuser à vos équipes ou clients
MIGHT YOU BE AFFECTED?
Turn knowledge into action.
How does this work?
It changes system components, sometimes the kernel or boot process, to conceal files, processes and connections while retaining the attacker's privileges.
REAL-WORLD EXAMPLE
« After an initial intrusion, a rootkit hides the attacker's account and tools. »
Typical sequence
- 1Gain elevated privileges
- 2Modify system components
- 3Conceal activity and preserve access
Warning signs
- System tools return inconsistent results
- Unknown drivers or modules
- Secure Boot alerts
How to protect yourself
- Apply patches and enable Secure Boot
- Use endpoint detection and integrity checks
- Reinstall from trusted media if infection is confirmed
If you think you are affected
Disconnect the device, preserve evidence and arrange an offline investigation. Deep compromise may require reinstalling from trusted media and changing every secret used on the device.
Last updated: 6 September 2026