SecurCheckCyber Center
Need help
Back to analysis tools
All cyber threats
Malware

Rootkit

Rootkit

Stealth software that hides its presence and grants deep access to a system.

Fiche de sensibilisationPrête à diffuser à vos équipes ou clients

MIGHT YOU BE AFFECTED?

Turn knowledge into action.

How does this work?

It changes system components, sometimes the kernel or boot process, to conceal files, processes and connections while retaining the attacker's privileges.

REAL-WORLD EXAMPLE

« After an initial intrusion, a rootkit hides the attacker's account and tools. »

Typical sequence

  1. 1Gain elevated privileges
  2. 2Modify system components
  3. 3Conceal activity and preserve access

Warning signs

  • System tools return inconsistent results
  • Unknown drivers or modules
  • Secure Boot alerts

How to protect yourself

  • Apply patches and enable Secure Boot
  • Use endpoint detection and integrity checks
  • Reinstall from trusted media if infection is confirmed

If you think you are affected

Disconnect the device, preserve evidence and arrange an offline investigation. Deep compromise may require reinstalling from trusted media and changing every secret used on the device.

Get help

Last updated: 6 September 2026