Security

Rootkit

Malware or a malicious tool designed to keep privileged access while hiding its activity. Its presence cannot be inferred from one symptom; investigation and recovery depend on the affected system.

How it works

A rootkit uses privileged access to conceal or maintain unauthorised control. It may hide files, processes or changes from ordinary tools. Some operate within the operating system, while deeper components can affect boot or firmware; the term does not specify one universal removal method.

A practical example

A compromised system may report normal-looking results because the component supplying those results has been altered. That is why checking a suspected rootkit only through the running system can be insufficient. A name in a security alert also needs interpretation in the product’s context.

What to check

Preserve the detection details and avoid experimenting with untrusted removal utilities. Use the security vendor’s supported assessment or an independent trusted recovery environment where appropriate. On a managed device, involve the administrator before changing boot settings, replacing firmware or reinstalling the operating system.

Limits and safe use

Ordinary crashes or unexplained files do not prove a rootkit. A system reinstall may be appropriate in some incidents but does not automatically resolve every firmware-level issue or protect stolen accounts. Plan backups, recovery keys and a trusted rebuild route before erasing data; specialist investigation may be required.

Technical sources

← All glossary terms