Tyton – Linux Kernel-Mode Rootkit Hunter for 4.4.0-31+

Linux Kernel-Mode Rootkit Hunter for 4.4.0-31+.For more information, visit Tyton’s website.Detected AttacksHidden ModulesSyscall Table HookingNetwork Protocol HookingNetfilter HookingZeroed Process InodesProcess Fops HookingInterrupt Descriptor Table HookingAdditional FeaturesNotifications: Users (including myself) do not actively monitor their journald logs, so a userland notification daemon has been included to monitor journald logs and display them to the user using libnotify. Notifications are enabled after install by XDG autorun, so if your DM does not have /etc/xdg/autostart it will fail.DKMS: Dynamic Kernel Module Support has been added for Arch and Fedora/CentOS (looking to expand in the near future). DKMS allows the (near) seamless upgrading of Kernel modules during kernel upgrades. This is mainly important for distributions that provide rolling releases or upgrade their kernel frequently.InstallingDependenciesLinux Kernel 4.4.0-31 or greaterCorresponding Linux Kernel HeadersGCCMakeLibnotifyLibsystemdPackage ConfigGTK3From SourceUbuntu/Debian/Kalisudo apt install linux-headers-$(uname -r) gcc make libnotify-dev pkg-config libgtk-3-dev libsystemd-devgit clone https://github.com/nbulischeck/tyton.gitcd tytonmakesudo insmod tyton.koNote: For Ubuntu 14.04, libsystemd-dev is named libsystemd-journal-dev.Archsudo pacman -S linux-headers gcc make libnotify libsystemd pkgconfig gtk3git clone https://github.com/nbulischeck/tyton.gitcd tytonmakesudo insmod tyton.koNote: It’s recommended to install Tyton through the AUR so you can benefit from DKMS.Fedora/CentOSdnf install kernel-devel gcc make libnotify libnotify-devel systemd-devel gtk3-devel gtk3git clone https://github.com/nbulischeck/tyton.gitcd tytonmakesudo insmod tyton.koKernel Module ArgumentsThe kernel module can be passed a specific timeout argument on insertion through the command line.To do this, run the command sudo insmod tyton.ko timeout=X where X is the number of minutes you would like the kernel module to wait before executing its scan again.AURTyton is available on the AUR here.You can install it using the AUR helper of your choice:yaourt -S tyton-dkms-gityay -S tyton-dkms-gitpakku -S tyton-dkms-gitDownload Tyton

Link: http://feedproxy.google.com/~r/PentestTools/~3/-SpNjyLloZM/tyton-linux-kernel-mode-rootkit-hunter.html