Intrusion Detection

Rootkit Hunter – security tool

rkhunter (Rootkit Hunter) is a Unix-based tool that scans for rootkits, backdoors and possible local exploits.

Specifically, rkhunter is a shell script which carries out various checks on the local system to try and detect known rootkits and malware. It also performs checks to see if commands have been modified, if the system startup files have been modified, and various checks on the network interfaces, including checks for listening applications.

rkhunter has been written to be as generic as possible, and so should run on most Linux and UNIX systems. It is provided with some support scripts should certain commands be missing from the system, and some of these are Perl scripts.

Key Features

  • Compares MD5 hashes of important files with known good ones in online database.
  • Searches for:
    • Default directories of rootkits.
    • Wrong permissions.
    • Hidden files.
    • Suspicious strings in kernel modules.
    • Special tests.

Website: rkhunter.sourceforge.net
Support: Mailing Lists
Developer: Michael Boelen
License: GNU General Public License

rkhunter is written in Perl. Learn Perl with our recommended free books and free tutorials.


Related Software

Anti-Malware Tools
ClamAVAntivirus engine for detecting trojans, viruses, malware and other threats
YARAPattern matching swiss knife for malware researchers
MaltrailMalicious traffic detection system
ClamTkGraphical frontend for ClamAV
LMDMalware scanner focusing on threats faced in shared hosted environments
phpMusselPHP-based anti-virus anti-trojan anti-malware solution
libredefenderAntivirus program using libclamav
RaspirusLightweight signature-based malware scanner
FastFinderFast suspicious file finder
Rootkit HunterScans for rootkits, backdoors and possible local exploits
UnhideForensic tool to find hidden processes and TCP/UDP ports
HostsblockMalware-blocking cronscript
chkrootkitLocally checks for signs of a rootkit
LenspectLightweight security threat scanner

Read our verdict in the software roundup.

Host-Based Intrusion Detection Systems
WazuhPlatform used for threat prevention, detection, and response
OSSECFull platform to monitor and control your systems.
AIDEAdvanced Intrusion Detection Environment
LogwatchPowerful and versatile log parser and analyzer
SamhainFile integrity checking and log file monitoring/analysis and more
SaganMulti-threads, high performance log analysis engine
TripwireSecurity and data integrity tool
rkhunterScans for rootkits, backdoors and possible local exploits
chkrootkitLocally checks for signs of a rootkit

Read our verdict in the software roundup.


Best Free and Open Source Software Explore our comprehensive directory of recommended free and open source software. Our carefully curated collection spans every major software category.

This directory is part of our ongoing series of informative articles for Linux enthusiasts. It features hundreds of detailed reviews, along with open source alternatives to proprietary solutions from major corporations such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk.

You’ll also find interesting projects to try, hardware coverage, free programming books and tutorials, and much more.

Know a useful open source Linux program that we haven’t covered yet? Let us know by completing this form.
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments