Anti-Malware Tools

Decloaker – reveal objects hidden by malware

Decloaker is a command-line security tool that reveals files, directories, processes, network sockets and kernel modules which malware attempts to hide from normal system utilities. It is particularly useful when investigating rootkits that alter the view presented by standard file, process or networking commands.

The software obtains information through several independent mechanisms so that discrepancies can be identified. Its file commands can list, read, copy, move, remove and inspect files without relying on libc, helping expose objects concealed by LD_PRELOAD-based rootkits that intercept ordinary library calls.

For supported filesystems, Decloaker can also inspect data directly through the underlying disk device. Dedicated scanning commands look for hidden files, hidden file content, hidden processes, suspicious processes, hidden sockets and hidden kernel modules. A broader system scan combines several of these checks to provide a more comprehensive view of possible concealment.

Network facilities can obtain connection information through netlink and inspect the kernel connection tracking table. Decloaker can also dump running tasks, open files and loaded kernel modules directly from kernel information rather than depending entirely on interfaces such as /proc. Comparing these independent sources can help expose inconsistencies created by malware attempting to hide its activity.

This is free and open source software.

Key Features

  • Detects hidden files and directories.
  • Detects hidden processes.
  • Looks for suspicious processes.
  • Detects hidden network sockets.
  • Looks for hidden kernel modules.
  • Checks files for hidden content.
  • Provides file operations that bypass libc.
  • Inspects supported filesystems directly through disk devices.
  • Lists network connections through netlink.
  • Dumps the kernel connection tracking table.
  • Dumps running tasks from kernel information.
  • Dumps open files.
  • Dumps loaded kernel modules.
  • Provides a combined system scanning mode.

Website: github.com/gustavo-iniguez-goya/decloaker
Support:
Developer: Gustavo Iñiguez Goya
License: GNU General Public License v3.0

Decloaker is written in C. Learn C with our recommended free books and free tutorials.


Related Software

Anti-Malware Tools
ClamAVAntivirus engine for detecting trojans, viruses, malware and other threats
YARA-XRe-incarnation of YARA
YARAPattern matching swiss knife for malware researchers
MaltrailMalicious traffic detection system
ClamTkGraphical frontend for ClamAV
LMDMalware scanner focusing on threats faced in shared hosted environments
phpMusselPHP-based anti-virus anti-trojan anti-malware solution
RaspirusLightweight signature-based malware scanner
FastFinderFast suspicious file finder
Rootkit HunterScans for rootkits, backdoors and possible local exploits
UnhideForensic tool to find hidden processes and TCP/UDP ports
HostsblockMalware-blocking cronscript
libredefenderAntivirus program using libclamav
LenspectLightweight security threat scanner
chkrootkitLocally checks for signs of a rootkit

Read our verdict in the software roundup.


Best Free and Open Source Software Explore our carefully curated directory of recommended free and open source software, covering every major software category.

The directory forms part of our extensive collection of articles for Linux enthusiasts. It includes hundreds of detailed reviews, together with free and open source alternatives to proprietary software from companies such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk.

LinuxLinks also covers interesting projects worth exploring, Linux-compatible hardware, free programming books and tutorials, and much more.

Know a useful free and open source Linux application that we haven’t covered? Tell us about it using our submission form.
Subscribe

Please read our Comment Policy before commenting.

Notify of
guest
0 Comments
Oldest
Newest Most Voted