Chkrootkit
Locally checks for signs of rootkits on Unix-like systems.
Open the official app on www.chkrootkit.org
This tool is hosted by its maintainers. Click below to open www.chkrootkit.org in a new tab — it's their official demo.
Browse security tools →What's next with Chkrootkit?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Chkrootkit?
Chkrootkit is an open-source Linux tool designed to detect rootkits by analyzing system binaries, network interfaces, and log files for signs of unauthorized modifications. Rootkits are malicious software suites that hide malware by tampering with system components, making them difficult to detect. This tool is primarily used by system administrators and cybersecurity professionals to identify compromised systems. It addresses the problem of stealthy malware that evades traditional detection methods by checking for anomalies in critical system files and processes. Chkrootkit is particularly valuable in environments where unauthorized access could lead to data breaches or system sabotage. Its ability to locally scan for rootkit signatures makes it a foundational tool in Linux security practices, despite its age and the emergence of newer alternatives.
How it works
Chkrootkit is a command-line utility that scans Linux systems for rootkit-related modifications. It leverages a collection of C programs and scripts to inspect binaries, kernel modules, and system logs for inconsistencies that may indicate rootkit presence. The tool is specifically designed to detect local rootkit infections, such as those involving LKM (Loadable Kernel Module) trojans, hidden processes, or altered system utilities. Its primary purpose is to provide an early warning system for security breaches by identifying subtle changes to critical system components. Chkrootkit checks system binaries for signs of tampering, such as modified utilities like `ifconfig`, `ps`, or `netstat`. It also monitors network interfaces for promiscuous mode activation, which is often used by sniffing malware. Additional capabilities include verifying the integrity of log files like `wtmp`, `lastlog`, and `utmp` to detect deletions or tampering.
How to use it
- 1Download the Chkrootkit source code from its repository or a trusted mirror. 2. Compile the tool using a C compiler, ensuring all required dependencies are installed. 3. Run the `chkrootkit` script with root privileges to initiate the scan. 4. Review the output for flagged anomalies, such as unexpected processes or modified binaries. Practical tips include running the tool after system compromises or during routine security audits. It is recommended to cross-reference findings with other tools like `rkhunter` for comprehensive coverage. Ensure the system's `/etc/hosts.equiv` and `.rhosts` files are secure to prevent unauthorized remote access.
What it can do
- rootkit detection
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/Magentron/chkrootkit
- license: GPL-2.0 — free to use
- privacy: Self-hosted — you control your data
Limitations
- For authorized use only — use on systems you own or have explicit permission to test.
- Limited detection capabilities for modern rootkits that use advanced obfuscation techniques
- High rate of false positives, requiring manual verification of flagged items
- Does not support real-time monitoring or continuous intrusion detection
- Depends on local execution, making it ineffective for remote system analysis
Understanding the result
Locally checks for signs of rootkits on Unix-like systems.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (MIT).
- Built with
- (Magentron/chkrootkit)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with Magentron/chkrootkit. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- GPL-2.0 License
Upstream project
Frequently asked
What types of rootkits does Chkrootkit detect?
Chkrootkit is designed to detect traditional rootkits, including LKM trojans, network sniffing tools, and kernel-level malware. It checks for modified binaries like `ifconfig`, `ps`, and `netstat`, as well as anomalies in system logs. Newer versions also include checks for UEFI bootkits and memory-resident processes, though it may not cover all modern rootkit variants.
How does Chkrootkit differentiate between legitimate system changes and rootkit modifications?
Chkrootkit compares system files against known rootkit signatures and checks for inconsistencies in file hashes or permissions. For example, it identifies if a binary has been replaced with a modified version by comparing its checksums against trusted sources. It also flags unusual process behaviors, such as unexpected network activity or hidden processes, which may indicate rootkit presence.
How do I run Chkrootkit on a Linux system?
First, download the source code from the official repository. Compile it using `gcc` with the command `gcc -o chkrootkit chkrootkit.c`. Run the tool as root with `sudo ./chkrootkit`. The script will analyze system binaries, network interfaces, and logs, outputting results to the terminal. Review the output for warnings or errors, and investigate flagged items further using tools like `strace` or `ltrace`.
How does Chkrootkit compare to alternatives like rkhunter?
Chkrootkit and rkhunter are both rootkit detection tools, but they differ in approach. Chkrootkit focuses on static analysis of binaries and system logs, while rkhunter includes dynamic checks and database-based signature matching. Chkrootkit is lighter and faster but may miss some modern rootkit variants. Rkhunter offers more comprehensive detection but requires more system resources. Both tools are complementary and are often used together for better coverage.
What should I do if Chkrootkit reports a false positive?
If a false positive is detected, verify the flagged file by comparing its checksum against known good versions. Use tools like `md5sum` or `sha256sum` to validate the file's integrity. If the file is legitimate, update Chkrootkit's signature database or adjust its configuration to reduce false alarms. For critical systems, combine Chkrootkit with other security tools for cross-verification.