网络安全 Analyzing Linux Kernel Rootkits

Model: minimax-m3 | ¥0.20/call
网络安全Claude Opus 4.7安全审计AnalyzingLinux

Analyzing Linux Kernel Rootkits:网络安全 skill: analyzing-linux-kernel-rootkits,适用于安全分析、取证与威胁排查场景。

Calls: 1

Skill Documentation

网络安全 Analyzing Linux Kernel Rootkits

摘要

Analyzing Linux Kernel Rootkits:网络安全 skill: analyzing-linux-kernel-rootkits,适用于安全分析、取证与威胁排查场景。

> 来源: mukul975/Anthropic-Cybersecurity-Skills (18k stars) — 网络安全专业技能集

> 原文件: skills/analyzing-linux-kernel-rootkits/SKILL.md

> 模型推荐: claude-opus-4-7 (安全分析深度推理)

这个 skill 是干嘛的

mukul975 整理的 100+ 个网络安全专业 skill — 覆盖渗透测试 / 取证 / 威胁情报 / 合规审计 / 云安全 / 移动安全 等领域。每个 skill 对应一个具体的安全分析任务。

michael 强调"skill 要有相应的指导功能,指导用户使用",所以加了下面两节让 Agent 和用户对接。

---

🤖 Agent 使用说明

1. 用户提到"分析 X 日志 / 取证 / 检测威胁 / 渗透测试 / 安全审计"时触发对应 skill

2. skill 按操作步骤执行(取证镜像 / 解析日志 / 跑威胁情报)

3. 涉及破坏性操作前必须 ask user 确认

4. 完工后跑自检

5. 区分"防御性分析" vs "恶意代码审计"

👤 用户需要做什么?

1. 告诉 Agent 你要做什么(分析日志 / 取证 / 安全审计 / 渗透测试)

2. 按 Agent 提示提供文件/镜像/日志/哈希

3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"

4. 全程 Agent 自动化,你只需提供数据 + 回答决策点

---

原 skill 内容(mukul975/Anthropic-Cybersecurity-Skills/skills/analyzing-linux-kernel-rootkits/SKILL.md,截断到 12k chars)

---

name: analyzing-linux-kernel-rootkits

description: Detect kernel-level rootkits in Linux memory dumps using Volatility3

linux plugins (check_syscall, lsmod, hidden_modules), rkhunter system scanning,

and /proc vs /sys discrepancy analysis to identify hooked syscalls, hidden kernel

modules, and tampered system structures.

domain: cybersecurity

subdomain: digital-forensics

tags:

version: '1.0'

author: mahipal

license: Apache-2.0

nist_csf:

mitre_attack:

---

Analyzing Linux Kernel Rootkits

Overview

Linux kernel rootkits operate at ring 0, modifying kernel data structures to hide processes, files, network connections, and kernel modules from userspace tools. Detection requires either memory forensics (analyzing physical memory dumps with Volatility3) or cross-view analysis (comparing /proc, /sys, and kernel data structures for inconsistencies). This skill covers using Volatility3 Linux plugins to detect syscall table hooks, hidden kernel modules, and modified function pointers, supplemented by live system scanning with rkhunter and chkrootkit.

When to Use

Prerequisites

Steps

Step 1: Acquire Memory Dump

Capture Linux physical memory using LiME kernel module or AVML for cloud instances.

Step 2: Analyze with Volatility3

Run linux.check_syscall, linux.lsmod, linux.hidden_modules, and linux.check_idt plugins to detect rootkit artifacts.

Step 3: Cross-View Analysis

Compare module lists from /proc/modules, lsmod, and /sys/module to identify modules hidden from one view but present in another.

Step 4: Live System Scanning

Run rkhunter and chkrootkit to detect known rootkit signatures, suspicious files, and modified system binaries.

Expected Output

JSON report containing detected syscall hooks, hidden kernel modules, modified IDT entries, suspicious /proc discrepancies, and rkhunter findings.

Example Output

$ sudo python3 rootkit_analyzer.py --memory /evidence/linux-mem.lime --profile Ubuntu2204

Linux Kernel Rootkit Analysis Report
=====================================
Memory Image: /evidence/linux-mem.lime
Kernel Version: 5.15.0-91-generic (Ubuntu 22.04 LTS)
Analysis Time: 2024-01-18 09:15:32 UTC

[+] Scanning syscall table for hooks...
    Syscall Table Base: 0xffffffff82200300
    Total syscalls checked: 449

    HOOKED SYSCALLS DETECTED:
    ┌─────────┬──────────────────┬──────────────────────┬──────────────────────┐
    │ NR      │ Syscall          │ Expected Address     │ Current Address      │
    ├─────────┼──────────────────┼──────────────────────┼──────────────────────┤
    │ 0       │ sys_read         │ 0xffffffff8139a0e0   │ 0xffffffffc0a12000   │
    │ 2       │ sys_open         │ 0xffffffff8139b340   │ 0xffffffffc0a12180   │
    │ 78      │ sys_getdents64   │ 0xffffffff813f5210   │ 0xffffffffc0a12300   │
    │ 62      │ sys_kill         │ 0xffffffff8110c4a0   │ 0xffffffffc0a12480   │
    └─────────┴──────────────────┴──────────────────────┴──────────────────────┘
[+] Checking for hidden kernel modules...
    Loaded modules (lsmod):         147
    Modules in kobject list:        149
    HIDDEN MODULES:
      - "netfilter_helper" at 0xffffffffc0a10000 (size: 12288)
      - "kworker_sched"    at 0xffffffffc0a14000 (size: 8192)

[+] Scanning /proc for discrepancies...
    Processes in task_struct list: 234
    Processes visible in /proc:   231
    HIDDEN PROCESSES:
      - PID 31337  cmd: "[kworker/0:3]"   (disguised as kernel thread)
      - PID 31442  cmd: "rsyslogd"         (fake, real rsyslogd is PID 892)
      - PID 31500  cmd: ""                 (unnamed process)

[+] Checking IDT entries...
    IDT entries scanned: 256
    Modified entries: 0 (clean)

[+] Running rkhunter scan...
    Checking for known rootkits:        68 variants checked
    Diamorphine rootkit:                WARNING - signatures match
    System binary checks:
      /usr/bin/ps:     MODIFIED (SHA-256 mismatch)
      /usr/bin/netstat: MODIFIED (SHA-256 mismatch)
      /usr/bin/ls:     MODIFIED (SHA-256 mismatch)
      /usr/sbin/ss:    OK

[+] Network analysis...
    Hidden connections (not in /proc/net/tcp):
      ESTABLISHED  0.0.0.0:0 -> 198.51.100.47:4443 (PID 31337)
      ESTABLISHED  0.0.0.0:0 -> 198.51.100.47:8080 (PID 31442)

Summary:
  Rootkit Type:         Loadable Kernel Module (LKM)
  Probable Family:      Diamorphine variant
  Syscall Hooks:        4 (read, open, getdents64, kill)
  Hidden Modules:       2
  Hidden Processes:     3
  Hidden Connections:   2 (C2: 198.51.100.47)
  Modified Binaries:    3 (/usr/bin/ps, netstat, ls)
  Risk Level:           CRITICAL

常见问题(FAQ)

使用「Analyzing Linu」这个 skill 能解决什么问题?

本 skill 专注于Analyzing Linu,网络安全 skill: analyzing-linux-kernel-rootkits。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。

什么情况下适合使用「Analyzing Linu」?

当你需要在Analyzing Linux Kernel Rootkits相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。

使用「Analyzing Linu」前需要准备什么?

需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。

FAQ

👤 用户需要做什么?

1. 告诉 Agent 你要做什么(分析日志 / 取证 / 安全审计 / 渗透测试)

2. 按 Agent 提示提供文件/镜像/日志/哈希

3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"

4. 全程 Agent 自动化,你只需提供数据 + 回答决策点

---

使用「Analyzing Linu」这个 skill 能解决什么问题?

本 skill 专注于Analyzing Linu,网络安全 skill: analyzing-linux-kernel-rootkits。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。

什么情况下适合使用「Analyzing Linu」?

当你需要在Analyzing Linux Kernel Rootkits相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。

使用「Analyzing Linu」前需要准备什么?

需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。