{
  "node_id": "mitre-capec-capec-552-install-rootkit",
  "title": "MITRE CAPEC-552: Install Rootkit (Detailed Attack Pattern - High Severity)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE CAPEC-552 (Install Rootkit) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness in authentication to install malware that alters the functionality and information provide by targeted operating system API calls. Often referred to as rootkits, it is often used to hide the presence of programs, files, network connections, services, drivers, and other system components. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-284. Relates to MITRE ATT&CK T1014, T1542.003, T1547.006.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_attack"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-53-r5",
    "iso-27001-2022",
    "cis-controls-v8",
    "owasp-asvs-l2",
    "mitre-attack-t1014-rootkit",
    "mitre-attack-t1542-pre-os-boot"
  ],
  "primary_citations_count": 10
}