Computer Security
[EN] securityvulns.ru
no-pyccku



RKDetect - behaviour based rootkit detection utility
updated since 12.05.2004
Published:08.09.2004
Source:offtopic1
SecurityVulns ID:3682
Description:Rkdetect is a little anomaly detection tool which can find services hidden by generic Windows rootkits like Hacker Defender. Tool very simply. It enumerates services on remote computer through WMI (user level) and Services Control Manager (kernel level), compare result and display difference. In this way we can find hidden services which usual used to start rootkit. Similar approach can be used to enumerate processes, files, registry keys and anything that rootkits can to hide. Rkdetect available here: Updated on 08.09.2004: Support for localized systems added. http://www.security.nnov.ru/files/rkdetect.zip
Original documentdocumentSergey V. Gordeychik, rkdetect updated (08.09.2004)
 documentSergey V. Gordeychik, RKDetect (12.05.2004)
Files:RKDetect - rootkit anomaly detector
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru