chkrootkit
TLDR
Scan system for rootkits
$ sudo chkrootkit
Quiet mode (show infections only)$ sudo chkrootkit -q
Expert mode with more details$ sudo chkrootkit -x
Use alternate root directory$ sudo chkrootkit -r [/mnt/system]
Test specific check$ sudo chkrootkit [chkwtmp]
List available tests$ chkrootkit -l
SYNOPSIS
chkrootkit [options] [test...]
DESCRIPTION
chkrootkit locally checks for signs of rootkits. Examines system binaries for modifications, checks for deleted log entries, LKM trojans, and promiscuous network interfaces. Detects 70+ rootkits.
PARAMETERS
-q
Quiet mode, show infections only-x
Expert mode, show additional info-r dir
Use alternate root directory-p dir1:dir2
Custom path for binaries-l
List available tests-n
Skip NFS mounted directories
TESTS
chkwtmp
Check wtmp deletionschklastlog
Check lastlog deletionsifpromisc
Check for promiscuous interfaceschkproc
Check for LKM trojansstrings
Quick strings check
CAVEATS
Not foolproof - advanced rootkits can hide. Use with rkhunter for comprehensive scanning. Set up cron jobs for regular scans. If infection found, isolate system and investigate.


