Detecting Rootkit Activity

Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques. Activates for requests involving rootkit detection, hidden process discovery, kernel integrity checking, or system call hook analysis.

26zl b31fc16 4 files · 32.8 KB Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/detecting-rootkit-activity commit b31fc16f10

Frequently asked questions

npx skillmds@latest add 26zl/detecting-rootkit-activity