Umbra Wiki attack-pattern attack-pattern/CAPEC-552
Back to wiki

CAPEC-552 — Install Rootkit

provenance: imported · ATT&CK: T1014 T1542.003 T1547.006 · CWE: CWE-284

CAPEC-552: Install Rootkit

MITRE CAPEC attack pattern

Status Draft
Typical severity High
Likelihood of attack Medium
Catalogue CAPEC 3.9 (2023-01-24)

Description

An adversary exploits a weakness in authentication to install malware that alters the functionality and information provide by targeted operating system API calls. Often referred to as rootkits, it is often used to hide the presence of programs, files, network connections, services, drivers, and other system components.

Where this sits in the chain

A finding maps to a weakness (CWE), a weakness is exploited by an attack pattern (CAPEC), and an attack pattern shows up in ATT&CK as observed adversary behaviour. This page is the middle hop.

Weaknesses exploited: CWE-284

ATT&CK techniques: T1014, T1542.003, T1547.006

Mitigations

  • Prevent adversary access to privileged accounts necessary to install rootkits.

Source