Hilko Bengen
@hillu@infosec.exchange
infosec.exchange
A friendly reminder: Don't be afraid of #Linux #rootkits.
I have just released version 0.3.0 of rk-expose, a modern self-contained #rootkit detection tool that uses several techniques to detect signs of process hiding, file hiding, file content tampering from kernel or user space and can be used for hunting in large, diverse environments. rk-expose is written in #Rust.
Notable changes include:
Clearer output formatGeneric improvements to process hiding detection to avoid false positivesImprovements to cgroupfs process hiding detectionsA Velociraptor artifactAn "auto" subcommand that runs checks using sensible defaults and interprets results