T1562.001

Impair Defenses: Disable or Modify Tools

eBPF rootkit and anti-analysis measures impair host visibility and tooling that would observe the implant.

discovered 2026-06-03
View on MITRE ATT&CK ↗

Seen in packages

Campaigns