<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Secure2S &#187; Rootkit Detectors</title>
	<atom:link href="http://secure2s.net/en/category/tools/rootkit-detectors/feed/" rel="self" type="application/rss+xml" />
	<link>http://secure2s.net/en</link>
	<description>Security Tools</description>
	<lastBuildDate>Sat, 10 Jul 2010 13:44:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>chkrootkit</title>
		<link>http://secure2s.net/en/tools/rootkit-detectors/chkrootkit/153/</link>
		<comments>http://secure2s.net/en/tools/rootkit-detectors/chkrootkit/153/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 09:37:26 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Rootkit Detectors]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=153</guid>
		<description><![CDATA[chkrootkit : Locally checks for signs of a rootkit chkrootkit is a flexible, portable tool that can check for many signs of rootkit intrusion on Unix-based systems. Its features include detecting binary modification, utmp/wtmp/lastlog modifications, promiscuous interfaces, and malicious kernel modules. Related posts:RKHunter IP Filter Sysinternals


Related posts:<ol><li><a href='http://secure2s.net/en/tools/rootkit-detectors/rkhunter/131/' rel='bookmark' title='Permanent Link: RKHunter'>RKHunter</a></li>
<li><a href='http://secure2s.net/en/tools/firewalls/ip-filter/208/' rel='bookmark' title='Permanent Link: IP Filter'>IP Filter</a></li>
<li><a href='http://secure2s.net/en/tools/rootkit-detectors/sysinternals/64/' rel='bookmark' title='Permanent Link: Sysinternals'>Sysinternals</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Frootkit-detectors%2Fchkrootkit%2F153%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Frootkit-detectors%2Fchkrootkit%2F153%2F&amp;style=normal&amp;service=retwt.me" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.chkrootkit.org/">chkrootkit</a> : Locally checks for signs of a rootkit<br />
chkrootkit is a flexible, portable tool that can check for many signs of rootkit intrusion on Unix-based systems. Its features include detecting binary modification, utmp/wtmp/lastlog modifications, promiscuous interfaces, and malicious kernel modules.</p>
<img src="http://secure2s.net/en/?ak_action=api_record_view&id=153&type=feed" alt="" />

<p>Related posts:<ol><li><a href='http://secure2s.net/en/tools/rootkit-detectors/rkhunter/131/' rel='bookmark' title='Permanent Link: RKHunter'>RKHunter</a></li>
<li><a href='http://secure2s.net/en/tools/firewalls/ip-filter/208/' rel='bookmark' title='Permanent Link: IP Filter'>IP Filter</a></li>
<li><a href='http://secure2s.net/en/tools/rootkit-detectors/sysinternals/64/' rel='bookmark' title='Permanent Link: Sysinternals'>Sysinternals</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/rootkit-detectors/chkrootkit/153/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RKHunter</title>
		<link>http://secure2s.net/en/tools/rootkit-detectors/rkhunter/131/</link>
		<comments>http://secure2s.net/en/tools/rootkit-detectors/rkhunter/131/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 09:29:23 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Rootkit Detectors]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=131</guid>
		<description><![CDATA[RKHunter : An Unix Rootkit Detector RKHunter is scanning tool that checks for signs of various pieces of nasty software on your system like rootkits, backdoors and local exploits. It runs many tests, including MD5 hash comparisons, default filenames used by rootkits, wrong file permissions for binaries, and suspicious strings in LKM and KLD modules. <a href='http://secure2s.net/en/tools/rootkit-detectors/rkhunter/131/'>[...]</a>


Related posts:<ol><li><a href='http://secure2s.net/en/tools/rootkit-detectors/tripwire/93/' rel='bookmark' title='Permanent Link: Tripwire'>Tripwire</a></li>
<li><a href='http://secure2s.net/en/tools/rootkit-detectors/chkrootkit/153/' rel='bookmark' title='Permanent Link: chkrootkit'>chkrootkit</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Frootkit-detectors%2Frkhunter%2F131%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Frootkit-detectors%2Frkhunter%2F131%2F&amp;style=normal&amp;service=retwt.me" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.rootkit.nl/projects/rootkit_hunter.html">RKHunter</a> : An Unix Rootkit Detector<br />
RKHunter is scanning tool that checks for signs of various pieces of nasty software on your system like rootkits, backdoors and local exploits. It runs many tests, including MD5 hash comparisons, default filenames used by rootkits, wrong file permissions for binaries, and suspicious strings in LKM and KLD modules.</p>
<img src="http://secure2s.net/en/?ak_action=api_record_view&id=131&type=feed" alt="" />

<p>Related posts:<ol><li><a href='http://secure2s.net/en/tools/rootkit-detectors/tripwire/93/' rel='bookmark' title='Permanent Link: Tripwire'>Tripwire</a></li>
<li><a href='http://secure2s.net/en/tools/rootkit-detectors/chkrootkit/153/' rel='bookmark' title='Permanent Link: chkrootkit'>chkrootkit</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/rootkit-detectors/rkhunter/131/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tripwire</title>
		<link>http://secure2s.net/en/tools/rootkit-detectors/tripwire/93/</link>
		<comments>http://secure2s.net/en/tools/rootkit-detectors/tripwire/93/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 08:59:09 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Rootkit Detectors]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=93</guid>
		<description><![CDATA[Tripwire : The grand-daddy of file integrity checkers A file and directory integrity checker. Tripwire is a tool that aids system administrators and users in monitoring a designated set of files for any changes. Used with system files on a regular (e.g., daily) basis, Tripwire can notify system administrators of corrupted or tampered files, so <a href='http://secure2s.net/en/tools/rootkit-detectors/tripwire/93/'>[...]</a>


Related posts:<ol><li><a href='http://secure2s.net/en/tools/rootkit-detectors/chkrootkit/153/' rel='bookmark' title='Permanent Link: chkrootkit'>chkrootkit</a></li>
<li><a href='http://secure2s.net/en/tools/basic-tools/lsof/121/' rel='bookmark' title='Permanent Link: LSoF'>LSoF</a></li>
<li><a href='http://secure2s.net/en/tools/vulnerability-scanners/nessus/3/' rel='bookmark' title='Permanent Link: Nessus'>Nessus</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Frootkit-detectors%2Ftripwire%2F93%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Frootkit-detectors%2Ftripwire%2F93%2F&amp;style=normal&amp;service=retwt.me" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.tripwire.com/">Tripwire</a> : The grand-daddy of file integrity checkers<br />
A file and directory integrity checker. Tripwire is a tool that aids system administrators and users in monitoring a designated set of files for any changes. Used with system files on a regular (e.g., daily) basis, Tripwire can notify system administrators of corrupted or tampered files, so damage control measures can be taken in a timely manner. Traditionally an open souce tool, Tripwire Corp is now focused on their commercial enterprise configuration control offerings. An open source Linux version can still be found at <a href="http://sourceforge.net/projects/tripwire/">SourceForge</a>.  UNIX users may also want to consider <a href="http://www.cs.tut.fi/%7Erammer/aide.html">AIDE</a>, which has been designed to be a free Tripwire replacement.  Or you may wish to investigate <a href="http://www.radmind.org/">Radmind</a>, <a href="http://sectools.org/tools3.html#rkhunter">RKHunter</a>, or <a href="http://sectools.org/tools3.html#chkrootkit">chkrootkit</a>.  Windows users may like <a href="http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx">RootkitRevealer</a> from <a href="http://sectools.org/index.html#sysinternals">Sysinternals</a>.</p>
<img src="http://secure2s.net/en/?ak_action=api_record_view&id=93&type=feed" alt="" />

<p>Related posts:<ol><li><a href='http://secure2s.net/en/tools/rootkit-detectors/chkrootkit/153/' rel='bookmark' title='Permanent Link: chkrootkit'>chkrootkit</a></li>
<li><a href='http://secure2s.net/en/tools/basic-tools/lsof/121/' rel='bookmark' title='Permanent Link: LSoF'>LSoF</a></li>
<li><a href='http://secure2s.net/en/tools/vulnerability-scanners/nessus/3/' rel='bookmark' title='Permanent Link: Nessus'>Nessus</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/rootkit-detectors/tripwire/93/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sysinternals</title>
		<link>http://secure2s.net/en/tools/rootkit-detectors/sysinternals/64/</link>
		<comments>http://secure2s.net/en/tools/rootkit-detectors/sysinternals/64/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 08:41:24 +0000</pubDate>
		<dc:creator>JraNil</dc:creator>
				<category><![CDATA[Rootkit Detectors]]></category>
		<category><![CDATA[Insecure]]></category>

		<guid isPermaLink="false">http://secure2s.net/en/?p=64</guid>
		<description><![CDATA[Sysinternals : An extensive collection of powerful windows utilities Sysinternals provides many small windows utilities that are quite useful for low-level windows hacking. Some are free of cost and/or include source code, while others are proprietary. Survey respondents were most enamored with: ProcessExplorer for keeping an eye on the files and directories open by any <a href='http://secure2s.net/en/tools/rootkit-detectors/sysinternals/64/'>[...]</a>


Related posts:<ol><li><a href='http://secure2s.net/en/tools/basic-tools/lsof/121/' rel='bookmark' title='Permanent Link: LSoF'>LSoF</a></li>
<li><a href='http://secure2s.net/en/tools/rootkit-detectors/tripwire/93/' rel='bookmark' title='Permanent Link: Tripwire'>Tripwire</a></li>
<li><a href='http://secure2s.net/en/tools/basic-tools/fport/151/' rel='bookmark' title='Permanent Link: Fport'>Fport</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Frootkit-detectors%2Fsysinternals%2F64%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsecure2s.net%2Fen%2Ftools%2Frootkit-detectors%2Fsysinternals%2F64%2F&amp;style=normal&amp;service=retwt.me" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.microsoft.com/technet/sysinternals/default.mspx">Sysinternals</a> : An extensive collection of powerful windows utilities<br />
Sysinternals provides many small windows utilities that are quite useful for low-level windows hacking. Some are free of cost and/or include source code, while others are proprietary. Survey respondents were most enamored with:</p>
<ul>
<li><a href="http://www.microsoft.com/technet/sysinternals/utilities/ProcessExplorer.mspx">ProcessExplorer</a> for keeping an eye on the files and directories open by any process (like <a href="http://sectools.org/tools2.html#lsof">LSoF</a> on UNIX).</li>
<li><a href="http://www.microsoft.com/technet/sysinternals/utilities/PsTools.mspx">PsTools</a> for managing (executing, suspending, killing, detailing) local and remote processes.</li>
<li><a href="http://www.microsoft.com/technet/sysinternals/utilities/Autoruns.mspx">Autoruns</a> for discovering what executables are set to run during system boot up or login.</li>
<li><a href="http://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx">RootkitRevealer</a> for detecting registry and file system API discrepancies that may indicate the presence of a user-mode or kernel-mode rootkit.</li>
<li><a href="http://www.microsoft.com/technet/sysinternals/utilities/TcpView.mspx">TCPView</a>, for viewing TCP and UDP traffic endpoints used by each process (like Netstat on UNIX).</li>
</ul>
<p><strong>Update:</strong> Microsoft <a href="http://www.winternals.com/Company/PressRelease92.aspx">acquired Sysinternals</a> in July 2006, <a href="http://www.winternals.com/Company/PressRelease92.aspx">promising</a> that “Customers will be able to continue building on Sysinternals&#8217; advanced utilities, technical information and source code”. Less than four months later, Microsoft <a href="http://seclists.org/dailydave/2006/q4/0134.html">removed</a> most of that source code.  Future product direction is uncertain.</p>
<img src="http://secure2s.net/en/?ak_action=api_record_view&id=64&type=feed" alt="" />

<p>Related posts:<ol><li><a href='http://secure2s.net/en/tools/basic-tools/lsof/121/' rel='bookmark' title='Permanent Link: LSoF'>LSoF</a></li>
<li><a href='http://secure2s.net/en/tools/rootkit-detectors/tripwire/93/' rel='bookmark' title='Permanent Link: Tripwire'>Tripwire</a></li>
<li><a href='http://secure2s.net/en/tools/basic-tools/fport/151/' rel='bookmark' title='Permanent Link: Fport'>Fport</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://secure2s.net/en/tools/rootkit-detectors/sysinternals/64/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
