Rootkit Hunter
linux security
A Unix-based tool that scans for rootkits, backdoors and possible local exploits by comparing SHA-1 hashes of important files.
rootkit detectionintegrity checkingsecurity scanning
Legal & Ethical Use
- Rootkit detection
- System integrity checking
- Security monitoring
- Incident response
Installation
bash
$
sudo apt install rkhunterBasic Commands
bash
$
sudo rkhunter --checkRun a full system check
bash
$
sudo rkhunter --updateUpdate definitions
bash
$
sudo rkhunter --propupdUpdate file properties database
Advantages
- Rootkit specific
- Regular updates
- Detailed logging
- Low overhead
Limitations
- False positives
- Manual review needed
- Not real-time