unhide - Unhide is a forensic tool to find hidden processes and TCP/UDP ports.

Website: http://www.security-projects.com/?Unhide
License: GPLv3+
Vendor: Atomicorp http://www.atomicorp.com
Description:
Unhide is a forensic tool to find processes and TCP/UDP ports hidden by
rootkits, Linux kernel modules or by other techniques. It includes two
utilities: unhide and unhide-tcp.

Unhide detects hidden processes using three techniques:

 - comparing the output of /proc and /bin/ps
 - comparing the information gathered from /bin/ps with the one gathered
   from system calls (syscall scanning)
 - full scan of the process ID space (PIDs bruteforcing)

unhide-tcp identifies TCP/UDP ports that are listening but are not listed
in /bin/netstat through brute forcing of all TCP/UDP ports available.

Packages:

unhide-20130526-4.fc12.art.x86_64 [559 KiB]
unhide-20130428-3.fc12.art.x86_64 [559 KiB]

Changelog:

by Support (2013-03-28):
- Update to 20130428
Copyright © 2005-2010 Atomicorp, Inc.