Intrusion Detection

chkrootkit – locally checks for signs of a rootkit

Last Updated on February 27, 2026

chkrootkit is a tool to locally check for signs of a rootkit.

It tests the following applications: aliens, asp, bindshell, lkm, rexedcs, sniffer, w55808, wted, scalper, slapper, z2, chkutmp, amd, basename, biff, chfn, chsh, cron, crontab, date, du, dirname, echo, egrep, env, find, fingerd, gpm, grep, hdparm, su, ifconfig, inetd, inetdconf, identd, init, killall, ldsopreload, login, ls, lsof, mail, mingetty, netstat, named, passwd, pidof, pop2, pop3, ps, pstree, rpcinfo, rlogind, rshd, slogin, sendmail, sshd, syslogd, tar, tcpd, tcpdump, top, telnetd, timed, traceroute, vdir, w, and write.

chkrootkit has been tested on: Linux 2.0.x, 2.2.x, 2.4.x and 2.6.x, FreeBSD 2.2.x, 3.x, 4.x, 5.x, 7.x and 10.x, OpenBSD 2.x, 3.x, 4.x and 5.x., NetBSD 1.6.x, Solaris 2.5.1, 2.6, 8.0 and 9.0, HP-UX 11, Tru64, BSDI and Mac OS X.

Includes:

  • chkrootkit: shell script that checks system binaries for rootkit modification.
  • ifpromisc.c: checks if the interface is in promiscuous mode.
  • chklastlog.c: checks for lastlog deletions.
  • chkwtmp.c: checks for wtmp deletions.
  • check_wtmpx.c: checks for wtmpx deletions. (Solaris only)
  • chkproc.c: checks for signs of LKM trojans.
  • chkdirs.c: checks for signs of LKM trojans.
  • strings.c: quick and dirty strings replacement.
  • chkutmp.c: checks for utmp deletions.

Website: github.com/Magentron/chkrootkit
Support:
Developer: Nelson Murilo, Klaus Steding
License:


Related Software

Anti-Malware Tools
ClamAVAntivirus engine for detecting trojans, viruses, malware and other threats
YARAPattern matching swiss knife for malware researchers
MaltrailMalicious traffic detection system
ClamTkGraphical frontend for ClamAV
LMDMalware scanner focusing on threats faced in shared hosted environments
phpMusselPHP-based anti-virus anti-trojan anti-malware solution
libredefenderAntivirus program using libclamav
RaspirusLightweight signature-based malware scanner
FastFinderFast suspicious file finder
Rootkit HunterScans for rootkits, backdoors and possible local exploits
UnhideForensic tool to find hidden processes and TCP/UDP ports
HostsblockMalware-blocking cronscript
chkrootkitLocally checks for signs of a rootkit
LenspectLightweight security threat scanner

Read our verdict in the software roundup.

Host-Based Intrusion Detection Systems
WazuhPlatform used for threat prevention, detection, and response
OSSECFull platform to monitor and control your systems.
AIDEAdvanced Intrusion Detection Environment
LogwatchPowerful and versatile log parser and analyzer
SamhainFile integrity checking and log file monitoring/analysis and more
SaganMulti-threads, high performance log analysis engine
TripwireSecurity and data integrity tool
rkhunterScans for rootkits, backdoors and possible local exploits
chkrootkitLocally checks for signs of a rootkit

Read our verdict in the software roundup.


Best Free and Open Source Software Explore our comprehensive directory of recommended free and open source software. Our carefully curated collection spans every major software category.

This directory is part of our ongoing series of informative articles for Linux enthusiasts. It features hundreds of detailed reviews, along with open source alternatives to proprietary solutions from major corporations such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk.

You’ll also find interesting projects to try, hardware coverage, free programming books and tutorials, and much more.

Discovered a useful open source Linux program that we haven’t covered yet? Let us know by completing this form.
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments