Analyzing Linux Kernel Rootkits

Detect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules), rkhunter system scanning, and /proc vs /sys discrepancy analysis to identify hooked syscalls, hidden kernel modules, and tampered system structures.

xalgord 8dd70b7 7.2 KB Updated

File contents

xalgord/xalgorix/tree/main/internal/tools/skills/data/digital-forensics/analyzing-linux-kernel-rootkits commit 8dd70b7b57

Frequently asked questions

npx skillmds@latest add xalgord/analyzing-linux-kernel-rootkits