Suspicious Kernel Module Load From World Writable Directory on Linux

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-09-19
Updated
2026-09-19

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects insmod or modprobe loading a kernel object from tmp or shared memory paths as used to install Linux rootkits described in Elastic rootkit detection engineering research. Loading a ko file from a world writable staging directory rather than the module tree is a strong indicator of kernel level implant deployment.

Related detections9 linkedT1014 — drag to rearrange
Suspicious Kernel Module Load Or Unload For Rootkit Deployment via PUMAKIT
Malicious VoidLink Kernel Module Load via Insmod (via process_creation)
Suspicious Fileless Execution From Memory File Descriptor via PUMAKIT
Malicious ABYSSWORKER EDR-Killer Driver Load via smuol.sys
Possible AF_ALG Privilege Escalation via algif_aead Module Load
Malicious ValleyRAT KernelQuick Rootkit Service and Shellcode Store Registry Keys
Malicious Koske Userland Rootkit Installation via ld.so.preload (via file_event)
Malicious TeamTNT prochider Rootkit Deployment as Shared Object (via file_event)
Malicious perfctl Rootkit Library Drop via ld.so.preload (via file_event)
Suspicious Kernel Module Load From World Writable Directory on Linux
Pivot detection · T1014 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.