BIOC Informational

Kernel modules loaded via compiled loader and .ko file

Instead of using insmod/depmod, an attacker can build a loader and load a kernel module; attackers may use kernel modules as rootkits.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Persistence
Status:
Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Boot or Logon Autostart Execution: Kernel Modules and Extensions (T1547.006)
Indicator:

Process action type = execution AND target process cmd = *.ko * , *.ko

Preventable: yes