Netskope Threat Labs

RootkitDrv

ATP Sandbox Adv. Heuristics

This generic detection identifies kernel mode rootkit drivers that hide malicious activity below the operating system to evade detection.

First seen
May 2022
Last seen
October 2026
Alert Name
Win32.Trojan.RootkitDrv
Win64.Trojan.RootkitDrv