Detecting rootkits

Subversive Technologies & Countermeasures

Jump to: navigation, search
Development
Author Jason Todd
Information Informative article
Maturity Perpetual development, in need of user contributions
Status No disputes
Legend

Contents

[edit] Detection

[edit] Guarding points of entry

[edit] External sources

  • Network
  • Flash drives, Floppies

[edit] Internal sources

[edit] Protecting memory

A rootkit is going to have to exist in memory at some point in able to produce the desired result.

  • System memory
  • Peripheral memory

[edit] Protecting storge

  • EEPROM
    • firmware
    • bios
  • flash memory
  • hard drives, bad sectors

[edit] Software tools integration

Most software packages for the windows platform now offer software suites that contain firewall, ids, virus scanner, malware detection, rookit detection, and a host of other utilties.

[edit] Appendix

Windows:

*nix:

Personal tools