Analyzing Linux Kernel Rootkits

Detect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules), rkhunter system scanning, and /proc vs /sys discrepancy analysis to identify hooked syscalls, hidden kernel modules, and tampered system structures.

26zl 7419d39 4 files · 25.9 KB Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/analyzing-linux-kernel-rootkits commit 7419d3933b

Frequently asked questions

npx skillmds@latest add 26zl/analyzing-linux-kernel-rootkits