Home > Repository > base > unhide (x86_64)
unhide: Forensic tool to find hidden processes and ports
Unhide is a forensic tool to find hidden processes and TCP/UDP ports by rootkits / LKMs or by another hidden technique.
Unhide (ps) - Detecting hidden processes. Implements six main techniques
1. Compare /proc vs /bin/ps output
2. Compare info gathered from /bin/ps with info gathered by walking thru the procfs.
3. Compare info gathered from /bin/ps with info gathered from syscalls (syscall scanning).
4. Full PIDs space ocupation (PIDs bruteforcing).
5. Compare /bin/ps output vs /proc, procfs walking and syscall.
Reverse search, verify that all thread seen by ps are also seen in the kernel.
6. Quick compare /proc, procfs walking and syscall vs /bin/ps output.
It's about 20 times faster than tests 1+2+3 but maybe give more false positives.
Unhide-TCP
Identify TCP/UDP ports that are listening but not listed in /bin/netstat doing brute forcing of all TCP/UDP ports availables.
Nome: | unhide |
Versione: |
20240510-1mamba |
Architettura: | x86_64 |
Gruppo: | Applications/Security |
Dimensione: | 1,17 MB |
URL di origine: | https://www.unhide-forensics.info/ |
RPM sorgente: | unhide |
Collegati | Fornisce | Rende obsoleti | Richiede | Raccomanda |
---|
unhide-debug
| unhide = 0:20240510-1mamba unhide(x86-64) = 0:20240510-1mamba
| | | |
File forniti/usr/lib/.build-id
/usr/lib/.build-id/3e
/usr/lib/.build-id/3e/cf1862deafca164415d4161038a770a1259d33
/usr/lib/.build-id/bb
/usr/lib/.build-id/bb/4ac78237e62e08ea6b1d8a88f6567504bd77e4
/usr/lib/.build-id/f1
/usr/lib/.build-id/f1/76c1a0778735350ec7f4f64731d4045c091ecf
/usr/sbin/unhide
/usr/sbin/unhide-tcp
/usr/sbin/unhide_rb
/usr/share/doc/unhide-20240510
/usr/share/doc/unhide-20240510/COPYING
/usr/share/man/man8/unhide-tcp.8.gz
/usr/share/man/man8/unhide.8.gz