#rootkit

4 posts · Last used 25d

Back to Timeline
Hilko Bengen @hillu@infosec.exchange · Jul 15, 2026
A friendly reminder: Don't be afraid of #Linux #rootkits. I have just released version 0.3.0 of rk-expose, a modern self-contained #rootkit detection tool that uses several techniques to detect signs of process hiding, file hiding, file content tampering from kernel or user space and can be used for hunting in large, diverse environments. rk-expose is written in #Rust. Notable changes include: Clearer output formatGeneric improvements to process hiding detection to avoid false positivesImprovements to cgroupfs process hiding detectionsA Velociraptor artifactAn "auto" subcommand that runs checks using sensible defaults and interprets results
0
0
0
clibm079 @clibm079@infosec.exchange · Jun 30, 2026
Revisiting Stuxnet: Research Notes Technical Analysis and Design Insights into the “hide files” mindset https://malwareanalysisspace.blogspot.com/2026/06/revisiting-stuxnet-research-notes.html?m=1 #Stuxnet #Rootkit #HideFiles
0
0
0
UmWerker 🕊 ☮️ 🤘 @UmWerker@hachyderm.io · Jun 12, 2026
Erst vor zwei Tagen #Manuskript installiert, war darin bereits ein Übeltäter versteckt. Das #bash-Skript legte dies offen. Eine erste Überprüfung lies nicht erkennen, dass die eigentliche #Backdoor schon nachgeladen wurde und aktiv ist. Ich wollte nun mit #ClamAV sicher gehen, doch die Installation ist mir viel zu kompliziert. Daran scheitere ich kläglich. Schon Schade auf Sicherheit zu verzichten, weil deren Nutzung maximal erschwert wird. #Arch #Linux #ArchLinux #AUR #Rootkit https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577
0
0
0

You've seen all posts