Rootkit & compromise indicators · Rust · pacman
UNDER
TOW
A calm surface. A dangerous current beneath it. Undertow goes looking.
The rkhunter/chkrootkit category, rebuilt in Rust: preload hooks, world-writable system files, and drift in SUID binaries, kernel modules and persistence points — plus a full pacman -Qkk integrity sweep. Detection only: it never deletes or modifies anything it finds.
01 / Checks
Six currents
worth fearing.
Indicators, not signatures: unexpected files, permissions and drift — the moves real compromises make. Five fast checks run in about a tenth of a second; the full pacman sweep runs on its own schedule.
| CHECK | WHAT IT CATCHES |
|---|---|
| /etc/ld.so.preload | Non-empty: the classic userspace-rootkit hook into libc that hides files, processes and connections from ls/ps/ss. Always critical — this file should just be empty. |
| world-writable | Anything anyone can write in /etc, /usr/bin, /usr/sbin or systemd unit dirs — a live privilege-escalation path. |
| SUID/SGID drift | A newly appeared SUID/SGID binary — one of the most common privilege-escalation backdoors. Baseline + drift, not a stale allowlist. |
| kernel module drift | A new module loaded since baseline — the signature move of a kernel-level rootkit. |
| persistence drift | New files in systemd units, cron, /etc/profile.d, shell rc files or XDG autostart — how malware survives a reboot. |
| pacman -Qkk | Every installed package's files against pacman's own records. Not every hit is malicious (icon caches cause benign mismatches) — it reports what pacman found, it doesn't guess intent. |
❯ undertow check✓ ld.so.preload absent / empty✓ world-writable 0 sensitive files! SUID/SGID drift + /usr/local/bin/helper✓ kernel modules no new modules! persistence drift + ~/.config/autostart/updater.desktop 2 indicator(s) — review, then `undertow update`exit 1 · 0.11s
02 / Ground rules
It never
looks away.
A security check that quietly absorbed today's compromise into tomorrow's "normal" would stop reporting it after the first alert. Undertow won't.
REPORTED UNTIL REVIEWED
check never moves the baseline. Drift is reported on every run until you explicitly update.
DETECTION ONLY
Never deletes, quarantines or modifies anything it finds. You decide what's real.
NO SYNTHETIC GUESSES
The pacman parser is tested against a real -Qkk warning captured on a live system, and the full drift cycle was verified on scratch dirs first.
03 / Setup
Drop
the line.
Baseline a known-good system, then check on a timer. Both check and pacman exit non-zero when something's found — built for systemd timers and alerting.
git clone https://github.com/cybercore-tech/undertow
cd undertow && cargo build --release
undertow init # SUID / module / persistence baselines
undertow check # fast checks, ~0.1s
undertow update # accept current state, after review
undertow pacman # the slow integrity sweep# enable/disable individual checks and choose which
# paths are scanned for world-writable files and
# SUID binaries — full schema in the file itself.
- Known limit: indicators, not behavior — no de-obfuscation.
- Known limit: a determined kernel rootkit can hide its module from
lsmod. - Pair with: SigilWard for file content integrity.
04 / Theme matrix
Choose
your depth.
Every Cybercore palette from the shared schema, grouped by family — plus Undertow's own signature mashups. Your pick follows you across Cybercore sites.