Are rkhunter and chrootkit still effective linux rootkit scanners?Tripwire and alternativesHow do I deal with a compromised server?Our security auditor is an idiot. How do I give him the information he wants?Crontab and rkhunter SchedulingRkhunter triggered last night warning for a possible infection. What next?Is there an open source equivalent of Windows software restriction policies for Linux?Heartbleed: What is it and what are options to mitigate it?RKHunter reported processes that are using deleted files or are listening on the networkWhat to do if rkhunter finds a possible rootkit?rkhunter reports suspicious activity /bin/usr/wget and killall permissions changed

How to chain Python function calls so the behaviour is as follows

Payment instructions allegedly from HomeAway look fishy to me

How water is heavier than petrol eventhough its molecular weight less than petrol?

Different pedals/effects for low strings/notes than high

Where does "0 packages can be updated." come from?

Can a user sell my software (MIT license) without modification?

Soft question: Examples where lack of mathematical rigour cause security breaches?

Frame failure sudden death?

What is the actual quality of machine translations?

Should I give professor gift at the beginning of my PhD?

How can drunken, homicidal elves successfully conduct a wild hunt?

How did students remember what to practise between lessons without any sheet music?

Passing multiple files through stdin (over ssh)

Can the poison from Kingsmen be concocted?

Confusion about off peak timings of London trains

HT12e: How is this a 2¹² encoder?

Find the Factorial From the Given Prime Relationship

Russian equivalents of "no love lost"

Why doesn't Adrian Toomes give up Spider-Man's identity?

Scrum Master role: Reporting?

Is it possible to 'live off the sea'

How did they achieve the Gunslinger's shining eye effect in Westworld?

Is an early checkout possible at a hotel before its reception opens?

How does a transformer increase voltage while decreasing the current?



Are rkhunter and chrootkit still effective linux rootkit scanners?


Tripwire and alternativesHow do I deal with a compromised server?Our security auditor is an idiot. How do I give him the information he wants?Crontab and rkhunter SchedulingRkhunter triggered last night warning for a possible infection. What next?Is there an open source equivalent of Windows software restriction policies for Linux?Heartbleed: What is it and what are options to mitigate it?RKHunter reported processes that are using deleted files or are listening on the networkWhat to do if rkhunter finds a possible rootkit?rkhunter reports suspicious activity /bin/usr/wget and killall permissions changed






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








0















AFAICT neither have had much activity since the first half of 2014. Are there any other open source linux root scanners out there or reasonable commercial alternatives?










share|improve this question






















  • I guess your question will be closed, as product recommendations are off-topic here.

    – gf_
    Jan 17 '16 at 13:45











  • The question in the title might be relevant, I'll leave that to the community. But there is softwarerecs.stackexchange.com for software product recommendations which are off-topic for SF.

    – HBruijn
    Jan 31 '16 at 15:07

















0















AFAICT neither have had much activity since the first half of 2014. Are there any other open source linux root scanners out there or reasonable commercial alternatives?










share|improve this question






















  • I guess your question will be closed, as product recommendations are off-topic here.

    – gf_
    Jan 17 '16 at 13:45











  • The question in the title might be relevant, I'll leave that to the community. But there is softwarerecs.stackexchange.com for software product recommendations which are off-topic for SF.

    – HBruijn
    Jan 31 '16 at 15:07













0












0








0








AFAICT neither have had much activity since the first half of 2014. Are there any other open source linux root scanners out there or reasonable commercial alternatives?










share|improve this question














AFAICT neither have had much activity since the first half of 2014. Are there any other open source linux root scanners out there or reasonable commercial alternatives?







security rootkit rkhunter






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Jan 17 '16 at 13:36









steveinatorxsteveinatorx

1013




1013












  • I guess your question will be closed, as product recommendations are off-topic here.

    – gf_
    Jan 17 '16 at 13:45











  • The question in the title might be relevant, I'll leave that to the community. But there is softwarerecs.stackexchange.com for software product recommendations which are off-topic for SF.

    – HBruijn
    Jan 31 '16 at 15:07

















  • I guess your question will be closed, as product recommendations are off-topic here.

    – gf_
    Jan 17 '16 at 13:45











  • The question in the title might be relevant, I'll leave that to the community. But there is softwarerecs.stackexchange.com for software product recommendations which are off-topic for SF.

    – HBruijn
    Jan 31 '16 at 15:07
















I guess your question will be closed, as product recommendations are off-topic here.

– gf_
Jan 17 '16 at 13:45





I guess your question will be closed, as product recommendations are off-topic here.

– gf_
Jan 17 '16 at 13:45













The question in the title might be relevant, I'll leave that to the community. But there is softwarerecs.stackexchange.com for software product recommendations which are off-topic for SF.

– HBruijn
Jan 31 '16 at 15:07





The question in the title might be relevant, I'll leave that to the community. But there is softwarerecs.stackexchange.com for software product recommendations which are off-topic for SF.

– HBruijn
Jan 31 '16 at 15:07










1 Answer
1






active

oldest

votes


















1














Can't comment on whether these "are still effective", but regarding (a) alternative(s), have a look at Linux Malware Detect aka LMD. Quoting the website:




Linux Malware Detect (LMD) is a malware scanner for Linux released under the GNU GPLv2 license, that is designed around the threats faced in shared hosted environments. It uses threat data from network edge intrusion detection systems to extract malware that is actively being used in attacks and generates signatures for detection. In addition, threat data is also derived from user submissions with the LMD checkout feature and from malware community resources. The signatures that LMD uses are MD5 file hashes and HEX pattern matches, they are also easily exported to any number of detection tools such as ClamAV.



The driving force behind LMD is that there is currently limited availability of open source/restriction free tools for Linux systems that focus on malware detection and more important that get it right. Many of the AV products that perform malware detection on Linux have a very poor track record of detecting threats, especially those targeted at shared hosted environments. [...]







share|improve this answer























    Your Answer








    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "2"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f749729%2fare-rkhunter-and-chrootkit-still-effective-linux-rootkit-scanners%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    1














    Can't comment on whether these "are still effective", but regarding (a) alternative(s), have a look at Linux Malware Detect aka LMD. Quoting the website:




    Linux Malware Detect (LMD) is a malware scanner for Linux released under the GNU GPLv2 license, that is designed around the threats faced in shared hosted environments. It uses threat data from network edge intrusion detection systems to extract malware that is actively being used in attacks and generates signatures for detection. In addition, threat data is also derived from user submissions with the LMD checkout feature and from malware community resources. The signatures that LMD uses are MD5 file hashes and HEX pattern matches, they are also easily exported to any number of detection tools such as ClamAV.



    The driving force behind LMD is that there is currently limited availability of open source/restriction free tools for Linux systems that focus on malware detection and more important that get it right. Many of the AV products that perform malware detection on Linux have a very poor track record of detecting threats, especially those targeted at shared hosted environments. [...]







    share|improve this answer



























      1














      Can't comment on whether these "are still effective", but regarding (a) alternative(s), have a look at Linux Malware Detect aka LMD. Quoting the website:




      Linux Malware Detect (LMD) is a malware scanner for Linux released under the GNU GPLv2 license, that is designed around the threats faced in shared hosted environments. It uses threat data from network edge intrusion detection systems to extract malware that is actively being used in attacks and generates signatures for detection. In addition, threat data is also derived from user submissions with the LMD checkout feature and from malware community resources. The signatures that LMD uses are MD5 file hashes and HEX pattern matches, they are also easily exported to any number of detection tools such as ClamAV.



      The driving force behind LMD is that there is currently limited availability of open source/restriction free tools for Linux systems that focus on malware detection and more important that get it right. Many of the AV products that perform malware detection on Linux have a very poor track record of detecting threats, especially those targeted at shared hosted environments. [...]







      share|improve this answer

























        1












        1








        1







        Can't comment on whether these "are still effective", but regarding (a) alternative(s), have a look at Linux Malware Detect aka LMD. Quoting the website:




        Linux Malware Detect (LMD) is a malware scanner for Linux released under the GNU GPLv2 license, that is designed around the threats faced in shared hosted environments. It uses threat data from network edge intrusion detection systems to extract malware that is actively being used in attacks and generates signatures for detection. In addition, threat data is also derived from user submissions with the LMD checkout feature and from malware community resources. The signatures that LMD uses are MD5 file hashes and HEX pattern matches, they are also easily exported to any number of detection tools such as ClamAV.



        The driving force behind LMD is that there is currently limited availability of open source/restriction free tools for Linux systems that focus on malware detection and more important that get it right. Many of the AV products that perform malware detection on Linux have a very poor track record of detecting threats, especially those targeted at shared hosted environments. [...]







        share|improve this answer













        Can't comment on whether these "are still effective", but regarding (a) alternative(s), have a look at Linux Malware Detect aka LMD. Quoting the website:




        Linux Malware Detect (LMD) is a malware scanner for Linux released under the GNU GPLv2 license, that is designed around the threats faced in shared hosted environments. It uses threat data from network edge intrusion detection systems to extract malware that is actively being used in attacks and generates signatures for detection. In addition, threat data is also derived from user submissions with the LMD checkout feature and from malware community resources. The signatures that LMD uses are MD5 file hashes and HEX pattern matches, they are also easily exported to any number of detection tools such as ClamAV.



        The driving force behind LMD is that there is currently limited availability of open source/restriction free tools for Linux systems that focus on malware detection and more important that get it right. Many of the AV products that perform malware detection on Linux have a very poor track record of detecting threats, especially those targeted at shared hosted environments. [...]








        share|improve this answer












        share|improve this answer



        share|improve this answer










        answered Jan 17 '16 at 13:44









        gf_gf_

        4,40221335




        4,40221335



























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Server Fault!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f749729%2fare-rkhunter-and-chrootkit-still-effective-linux-rootkit-scanners%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

            Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

            Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020