<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=RKHUNTER_-_Documentation</id>
	<title>RKHUNTER - Documentation - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=RKHUNTER_-_Documentation"/>
	<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=RKHUNTER_-_Documentation&amp;action=history"/>
	<updated>2026-05-02T18:43:14Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.44.2</generator>
	<entry>
		<id>https://it-arts.net/index.php?title=RKHUNTER_-_Documentation&amp;diff=1049&amp;oldid=prev</id>
		<title>Admin: Text replacement - &quot;Category:Wiki&quot; to &quot;Category:Wiki

&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;
&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=RKHUNTER_-_Documentation&amp;diff=1049&amp;oldid=prev"/>
		<updated>2026-01-17T08:36:33Z</updated>

		<summary type="html">&lt;p&gt;Text replacement - &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;&amp;quot; to &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; &amp;quot;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 08:36, 17 January 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Basic Usage ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Basic Usage ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
	<entry>
		<id>https://it-arts.net/index.php?title=RKHUNTER_-_Documentation&amp;diff=506&amp;oldid=prev</id>
		<title>Admin: Created page with &quot;Category:Wiki  == Basic Usage ==  The most basic command to run rkhunter is as follows:   &lt;nowiki&gt; rkhunter --check&lt;/nowiki&gt;  This runs a full scan of the system and checks for rootkits, hidden files, and other potential security risks. It may take some time to complete, depending on the system size.  == Running rkhunter with Options ==  The command supports a wide range of options to customize the scan. Some of the most commonly used options are:  === Running a Chec...&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=RKHUNTER_-_Documentation&amp;diff=506&amp;oldid=prev"/>
		<updated>2025-12-14T08:36:18Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  == Basic Usage ==  The most basic command to run rkhunter is as follows:   &amp;lt;nowiki&amp;gt; rkhunter --check&amp;lt;/nowiki&amp;gt;  This runs a full scan of the system and checks for rootkits, hidden files, and other potential security risks. It may take some time to complete, depending on the system size.  == Running rkhunter with Options ==  The command supports a wide range of options to customize the scan. Some of the most commonly used options are:  === Running a Chec...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[Category:Wiki]]&lt;br /&gt;
&lt;br /&gt;
== Basic Usage ==&lt;br /&gt;
&lt;br /&gt;
The most basic command to run rkhunter is as follows:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
rkhunter --check&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This runs a full scan of the system and checks for rootkits, hidden files, and other potential security risks. It may take some time to complete, depending on the system size.&lt;br /&gt;
&lt;br /&gt;
== Running rkhunter with Options ==&lt;br /&gt;
&lt;br /&gt;
The command supports a wide range of options to customize the scan. Some of the most commonly used options are:&lt;br /&gt;
&lt;br /&gt;
=== Running a Check with Verbose Output ===&lt;br /&gt;
To run rkhunter with detailed output, use the following command:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
rkhunter --check --verbose&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This provides more detailed information about each check and any issues it finds.&lt;br /&gt;
&lt;br /&gt;
=== Check a Specific Directory or File ===&lt;br /&gt;
If you wish to check a specific directory or file, use the `--file` or `--dir` option, respectively:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
rkhunter --check --dir /home/user&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
or&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
rkhunter --check --file /etc/passwd&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Update Rootkit Hunter Database ===&lt;br /&gt;
Rootkit Hunter relies on a database of known rootkits. To ensure it has the latest signatures, update the database with the following command:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
rkhunter --update&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will download the latest rootkit definitions from the rkhunter servers.&lt;br /&gt;
&lt;br /&gt;
=== Exclude Specific Tests ===&lt;br /&gt;
If you want to skip certain tests during the check, you can exclude them with the `--skip` option. For example, to skip the file system checks:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
rkhunter --check --skip fs&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You can exclude multiple tests by separating them with commas:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
rkhunter --check --skip fs,sysctl&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Enable Debugging Mode ===&lt;br /&gt;
If you are troubleshooting or need more detailed logging for analysis, use the `--debug` flag:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
rkhunter --check --debug&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will generate debug output, which can be helpful in identifying issues with the tool or system configuration.&lt;br /&gt;
&lt;br /&gt;
== Configuration File ==&lt;br /&gt;
&lt;br /&gt;
rkhunter stores its configuration settings in a configuration file, usually located at `/etc/rkhunter.conf`. This file can be edited to change various behavior of the tool. Key configuration options include:&lt;br /&gt;
&lt;br /&gt;
=== Disabling Specific Checks ===&lt;br /&gt;
To disable certain tests by default, you can edit the configuration file and comment out or set options to `false`. For example, to disable the &amp;quot;hidden file&amp;quot; check:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
# Disable check for hidden files&lt;br /&gt;
HIDDEN_FILE_CHECK=false&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Setting Email Notifications ===&lt;br /&gt;
You can configure rkhunter to send email notifications after a scan completes. To do so, edit the following settings in the configuration file:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
MAIL_ON_WARN=true&lt;br /&gt;
MAIL_CMD=&amp;quot;/usr/bin/mail -s &amp;#039;Rootkit Hunter Warning&amp;#039; user@example.com&amp;quot;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Ensure that the mail utility is properly configured on your system for this feature to work.&lt;br /&gt;
&lt;br /&gt;
=== Specifying the Log File ===&lt;br /&gt;
By default, rkhunter logs its output to `/var/log/rkhunter.log`. You can change the log file location by modifying the following entry in the configuration file:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
LOGFILE=&amp;quot;/var/log/custom_rkhunter.log&amp;quot;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Viewing Log Files ==&lt;br /&gt;
&lt;br /&gt;
After running a scan, rkhunter logs the results to a log file. To view the log and check for potential issues, use:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
cat /var/log/rkhunter.log&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
or, if you have configured a custom log file:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
cat /var/log/custom_rkhunter.log&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For easier reading, you can filter the logs for warnings or errors:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
grep &amp;quot;Warning&amp;quot; /var/log/rkhunter.log&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
or&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
grep &amp;quot;Warning&amp;quot; /var/log/custom_rkhunter.log&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Automated Scheduling with Cron ==&lt;br /&gt;
&lt;br /&gt;
To automate rkhunter scans, it is common to use cron jobs to run rkhunter at regular intervals. Here&amp;#039;s an example of how to run rkhunter daily:&lt;br /&gt;
&lt;br /&gt;
1. Edit the crontab for root by running:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
sudo crontab -e&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2. Add the following line to schedule a daily scan at 2 AM:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
0 2 * * * /usr/bin/rkhunter --check --quiet&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will run rkhunter daily at 2 AM without outputting anything unless a problem is found.&lt;br /&gt;
&lt;br /&gt;
== Common Issues and Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
=== False Positives ===&lt;br /&gt;
rkhunter may occasionally flag certain files or directories as suspicious, even if they are legitimate. In such cases, you can ignore those warnings by adding the affected files to the ignore list in the configuration file. For example:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
# Ignore false positive for /usr/bin/suspicious_file&lt;br /&gt;
IGNORE_FILES=&amp;quot;/usr/bin/suspicious_file&amp;quot;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Permissions Issues ===&lt;br /&gt;
rkhunter needs to run with root privileges to perform most of its checks. Ensure you are running the command as root or with sudo:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
sudo rkhunter --check&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If permissions are incorrect for system files, rkhunter might not be able to check them properly, resulting in incomplete scans.&lt;br /&gt;
&lt;br /&gt;
=== Outdated Database ===&lt;br /&gt;
An outdated rootkit database can lead to missed detections. Regularly run the `--update` command to keep the database current:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
sudo rkhunter --update&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/Truecrypt/RKHunter GitHub Repository]&lt;br /&gt;
* [https://rkhunter.sourceforge.io/ Official Website]&lt;br /&gt;
* [https://man7.org/linux/man-pages/man1/rkhunter.1.html Manual Page]&lt;br /&gt;
* [https://www.debian.org/doc/manuals/securing-debian-manual/ch06.en.html Securing Debian Manual]&lt;br /&gt;
* [https://wiki.archlinux.org/title/Rootkit_Hunter ArchWiki: Rootkit Hunter]&lt;/div&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
</feed>