RKAnalyzer - kernel level rootkit analyzer ! - The Hacker News
Loading
Sign up for Quick Updates

RKAnalyzer - kernel level rootkit analyzer !

Posted by: Mohit Kumar onThursday, May 19, 2011
Follow Us

RKAnalyzer - kernel level rootkit analyzer !

RKAnalyzer is a kernel level rootkit analyzer and defender using Hardware Virtualization Techniques, based on the BitVisor Project(A VMM developed by Tsukuba University and open-sourced under BSD License).

It tries to monitor kernel level rootkits' actions and log them. What differs RKAnalyzer with tranditional detection softwares(i.e. Rootkit Revealer, IceSword) is that RKAnalyzer actively intercepts rootkit actions, rather than reacting to rootkit after already infected. Also, RKAnalyzer support analysis mode, which differs from defend mode by presenting a much more transparent environment, in which rootkit would consider itself running without being monitored.

How to Use : http://code.google.com/p/rkanalyzer/wiki/HowToUse
Download : http://rkanalyzer.googlecode.com/svn/
Posted in Categories: , , ,

Author Info

photo of Mohit Kumar

aka 'Unix Root' is Founder and Editor-in-chief of 'The Hacker News'. He is a Security Researcher and Analyst, with experience in various aspects of Information Security. Other than this : He is an Internet Activist, Strong supporter of Anonymous & Wikileaks. Follow him @ Twitter | LinkedIn | | | Facebook Profile