Rootkit Hunter
Scan systems for rootkits, backdoors, and local exploits.
Open the official app on rkhunter.sourceforge.net
This tool is hosted by its maintainers. Click below to open rkhunter.sourceforge.net in a new tab — it's their official demo.
Browse security tools →What's next with Rootkit Hunter?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Rootkit Hunter?
Rootkit Hunter is an open-source security tool designed to detect rootkits and other malicious software on Unix-like systems. It provides a comprehensive framework for identifying hidden threats that traditional antivirus tools may miss. The tool is primarily used by system administrators, cybersecurity professionals, and organizations maintaining critical infrastructure to ensure system integrity. Rootkit Hunter addresses the challenge of detecting stealthy malware that can evade standard security measures by leveraging signature-based scanning, file integrity checks, and process monitoring. It is particularly valuable in environments where unauthorized access or persistent threats could compromise data confidentiality and system stability.
How it works
Rootkit Hunter is a command-line utility that scans systems for signs of rootkits, which are collections of malicious software designed to conceal their presence and maintain persistent access to compromised systems. It is built to complement existing security tools by focusing on low-level system artifacts that rootkits often manipulate. The tool's primary purpose is to detect covert malware, hidden processes, and modified system files that may indicate a rootkit infection. It is particularly effective in identifying threats that evade standard antivirus scans by hiding within legitimate system processes or kernel modules. Rootkit Hunter performs signature-based detection of known rootkits, compares system files against trusted baselines, and checks for suspicious process behaviors. It also verifies the integrity of critical system files and directories, such as /bin, /sbin, and /lib, to identify unauthorized modifications. Additionally, it can scan for hidden processes, network connections, and suspicious log entries that may indicate a compromise.
How to use it
- 1Download the install.sh script from the archived GitHub repository or clone the repository. 2. Run the script with your email address as an argument (e.g.,./install.sh user@example.com) to automate dependency installation and configuration. 3. Execute the rootkit scan using the rkhunter command, which will analyze system files, processes, and logs. 4. Review the generated reports in /tmp/rkhunter for detailed findings and remediation steps. Practical tips: Ensure all dependencies (e.g., curl, mailx) are installed beforehand. Customize the temporary directory or logging settings in the install script if needed. Regularly update the rootkit signature database to improve detection accuracy.
What it can do
- rootkit detection
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/installation/rkhunter
- license: GPL-2.0 — free to use
- privacy: Self-hosted — you control your data
Limitations
- For authorized use only — use on systems you own or have explicit permission to test.
- The tool's repository is archived and read-only, limiting access to updates and community contributions.
- It relies on signature-based detection, which may miss zero-day exploits or custom rootkit variants.
- Manual configuration is required for advanced settings, such as custom signature databases or log paths.
- It does not provide real-time monitoring or behavioral analysis of running processes.
Understanding the result
Scan systems for rootkits, backdoors, and local exploits.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (MIT).
- Built with
- (installation/rkhunter)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with installation/rkhunter. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- GPL-2.0 License
Upstream project
Frequently asked
How do I install Rootkit Hunter on a Linux system?
To install Rootkit Hunter, download the install.sh script from the archived GitHub repository or clone the repository. Run the script with your email address as an argument (e.g., ./install.sh user@example.com) to automate dependency installation. The script will install required tools like curl, mailx, and TAR, then configure the tool for system scanning. Verify the installation by checking the /tmp/rkhunter directory for logs and running the rkhunter command manually.
How does Rootkit Hunter detect rootkits?
Rootkit Hunter uses a combination of signature-based detection, file integrity checks, and process monitoring. It compares system files against a database of known rootkit signatures and checks for unauthorized modifications to critical binaries. The tool also scans for hidden processes, suspicious network connections, and anomalies in system logs that may indicate a rootkit presence. Regular updates to the signature database are essential to detect new threats.
How do I run a rootkit scan with Rootkit Hunter?
After installation, execute the rkhunter command in the terminal. This will initiate a scan of system files, processes, and logs. The scan includes checking for modified binaries, hidden processes, and suspicious network activity. Review the output in the /tmp/rkhunter directory for detailed findings. Use the --version option to verify the tool's version and ensure it is up to date with the latest signature database.
How does Rootkit Hunter compare to alternatives like chkrootkit?
Rootkit Hunter and chkrootkit both detect rootkits but differ in approach. Rootkit Hunter offers more comprehensive features, including file integrity checks, process monitoring, and automated email alerts. It also supports periodic updates to its signature database, whereas chkrootkit relies on static signature files. Rootkit Hunter is more suited for modern Linux environments, while chkrootkit may lack support for newer distributions and advanced detection methods.
What should I do if Rootkit Hunter reports a false positive?
If Rootkit Hunter flags a false positive, review the affected files and compare them against known good baselines. Use the --checkall option to re-scan the system and verify the results. If the file is a legitimate system update or patch, update the tool's configuration to exclude it from future scans. Manually adjust the signature database or whitelist the file to prevent repeated false alarms.