Files
atomic-red-team-gs/Linux/Defense_Evasion/Rootkits.md
T
JeremyNGalloway 08de1f2ead Initial upload
2018-02-27 11:07:04 -06:00

292 B

Rootkits

MITRE ATT&CK Technique: T1014

Loadable Kernel Module based Rootkit

Input:

sudo insmod MODULE.ko

OR

Input:

sudo modprobe MODULE.ko

LD_PRELOAD based Rootkit

Input:

export LD_PRELOAD=$PWD/libmy_r00tkit.so