Chkrootkit is a very useful tool that can check for many signs of rootkit intrusion on Unix-based systems. It checks system binaries for rootkit modification and if the interface is in promiscuous mode. Other useful features include checks for wtmp/wtmpx/utmp/lastlog modifications and deletion.
Homepage
Post a review