Analyzing Linux Kernel Rootkits

Detect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules), rkhunter system scanning, and /proc vs /sys discrepancy analysis to identify hooked syscalls, hidden kernel modules, and tampered system structures.

agentflocks 6b89330 5 files · 27.6 KB Updated

File contents

agentflocks/flocks/tree/main/.flocks/flockshub/plugins/skills/Anthropic-Cybersecurity-Skills/analyzing-linux-kernel-rootkits commit 6b89330605

Frequently asked questions

npx skillmds@latest add agentflocks/analyzing-linux-kernel-rootkits