[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#881414: ITP prochunter -- find hidden processes on Linux



Package: wnpp
Owner: "Samuel Henrique" <samueloph@gmail.com>
Severity: wishlist

​* Package name    : prochunter
  Upstream Author : nowayout <spartak@autistici.org>
* URL             : https://gitlab.com/nowayout/prochunter
* License         : GPLv2
  Programming Lang: Python, C
  Description     : Find hidden process with all userspace and most of the kernelspace rootkits

​Prochunter aims to find hidden process with all userspace and most of the kernelspace rootkits.
This tool is composed of a kernel module that prints out all running processes walking the task_struct list and creates /sys/kernel/proc_hunter/set entry. A python script that
invokes
the kernel function and diffs the module output with processes list collected from userspace (/proc walking).​

​I intend to maintain this package under the pkg-security team.​


--
Samuel Henrique <samueloph>

Reply to: