Rootkit & compromise indicators · Rust · pacman

UNDER
TOW

A calm surface. A dangerous current beneath it. Undertow goes looking.

The rkhunter/chkrootkit category, rebuilt in Rust: preload hooks, world-writable system files, and drift in SUID binaries, kernel modules and persistence points — plus a full pacman -Qkk integrity sweep. Detection only: it never deletes or modifies anything it finds.

◆ ≈0.1S FAST CHECKS◆ BASELINE DRIFT◆ READ-ONLY◆ MIT

01 / Checks

Six currents
worth fearing.

Indicators, not signatures: unexpected files, permissions and drift — the moves real compromises make. Five fast checks run in about a tenth of a second; the full pacman sweep runs on its own schedule.

CHECKWHAT IT CATCHES
/etc/ld.so.preloadNon-empty: the classic userspace-rootkit hook into libc that hides files, processes and connections from ls/ps/ss. Always critical — this file should just be empty.
world-writableAnything anyone can write in /etc, /usr/bin, /usr/sbin or systemd unit dirs — a live privilege-escalation path.
SUID/SGID driftA newly appeared SUID/SGID binary — one of the most common privilege-escalation backdoors. Baseline + drift, not a stale allowlist.
kernel module driftA new module loaded since baseline — the signature move of a kernel-level rootkit.
persistence driftNew files in systemd units, cron, /etc/profile.d, shell rc files or XDG autostart — how malware survives a reboot.
pacman -QkkEvery installed package's files against pacman's own records. Not every hit is malicious (icon caches cause benign mismatches) — it reports what pacman found, it doesn't guess intent.
● ● ●   undertow checkSCANNING
❯ undertow check✓ ld.so.preload        absent / empty✓ world-writable       0 sensitive files! SUID/SGID drift      + /usr/local/bin/helper✓ kernel modules       no new modules! persistence drift    + ~/.config/autostart/updater.desktop 2 indicator(s) — review, then `undertow update`exit 1 · 0.11s

02 / Ground rules

It never
looks away.

A security check that quietly absorbed today's compromise into tomorrow's "normal" would stop reporting it after the first alert. Undertow won't.

◆ STICKY DRIFT

REPORTED UNTIL REVIEWED

check never moves the baseline. Drift is reported on every run until you explicitly update.

◆ HANDS OFF

DETECTION ONLY

Never deletes, quarantines or modifies anything it finds. You decide what's real.

◆ TESTED ON REAL DATA

NO SYNTHETIC GUESSES

The pacman parser is tested against a real -Qkk warning captured on a live system, and the full drift cycle was verified on scratch dirs first.

03 / Setup

Drop
the line.

Baseline a known-good system, then check on a timer. Both check and pacman exit non-zero when something's found — built for systemd timers and alerting.

BUILD + RUN
git clone https://github.com/cybercore-tech/undertow
cd undertow && cargo build --release

undertow init      # SUID / module / persistence baselines
undertow check     # fast checks, ~0.1s
undertow update    # accept current state, after review
undertow pacman    # the slow integrity sweep
~/.config/undertow/config.toml
# enable/disable individual checks and choose which
# paths are scanned for world-writable files and
# SUID binaries — full schema in the file itself.
  • Known limit: indicators, not behavior — no de-obfuscation.
  • Known limit: a determined kernel rootkit can hide its module from lsmod.
  • Pair with: SigilWard for file content integrity.

04 / Theme matrix

Choose
your depth.

Every Cybercore palette from the shared schema, grouped by family — plus Undertow's own signature mashups. Your pick follows you across Cybercore sites.

NOW RUNNING · …
…
dev@cybercoretech.net