Analyzing Linux Kernel Rootkits

Detect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules), rkhunter system scanning, and /proc vs /sys discrepancy analysis to identify hooked syscalls, hidden kernel modules, and tampered system structures.

Mikaru0Mystic Updated

File contents

Mikaru0Mystic/sectinel/tree/main/arsenal/Anthropic-Cybersecurity-Skills/skills/analyzing-linux-kernel-rootkits commit 6b89330605

Frequently asked questions

npx skillmds@latest add mikaru0mystic/analyzing-linux-kernel-rootkits