# How to Use Rkhunter for Rootkit Detection in Linux: Complete Setup Guide

> Learn how to use Rkhunter for rootkit detection in Linux with this complete setup guide. Secure your system by identifying suspicious files and backdoors effectively.

- Repository: [IMTheNachoMan/How-To-Secure-A-Linux-Server](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server)
- Tags: how-to-guide
- Published: 2026-05-14

---

**Rkhunter (Rootkit Hunter) is a lightweight command-line scanner that detects rootkits, backdoors, and suspicious files by comparing file hashes against a built-in database and verifying system binaries without requiring kernel modules.**

Securing a Linux server requires proactive malware detection and integrity monitoring. According to the `imthenachoman/How-To-Secure-A-Linux-Server` repository, implementing **Rkhunter for rootkit detection in Linux** provides a robust defense layer that scans for hidden processes, suspicious strings, and compromised system files. This guide walks through the complete installation, configuration, and maintenance workflow based on the repository's hardening recommendations.

## Installing Rkhunter on Linux

Rkhunter is packaged for most Debian-based distributions and installs the main binary to `/usr/bin/rkhunter` alongside default configuration files under `/etc/`.

```bash
sudo apt install rkhunter

```

This creates the primary configuration file at [`/etc/rkhunter.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/rkhunter.conf) and package defaults at `/etc/default/rkhunter`.

## Preserving and Configuring Rkhunter Settings

### Backing Up Original Configuration Files

Before modifying any settings, preserve the vendor-provided configurations to enable rollback if needed. The repository recommends timestamped backups for the defaults file and a `.local` copy for the main configuration.

```bash

# Backup the package defaults file

sudo cp -p /etc/default/rkhunter /etc/default/rkhunter-COPY-$(date +"%Y%m%d%H%M%S")

# Create a local configuration file for custom settings

sudo cp -p /etc/rkhunter.conf /etc/rkhunter.conf.local

```

### Creating Local Configuration Overrides

Instead of editing [`/etc/rkhunter.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/rkhunter.conf) directly, place custom settings in `/etc/rkhunter.conf.local`. This ensures vendor updates do not overwrite your changes while enabling tailored security policies.

Add the following key parameters to `/etc/rkhunter.conf.local`:

- **`UPDATE_MIRRORS=1`** – Enables automatic mirror updates for signature files.
- **`MIRRORS_MODE=0`** – Uses the default mirror selection algorithm.
- **`MAIL-ON-WARNING=root`** – Routes email alerts to the system administrator.
- **`COPY_LOG_ON_ERROR=1`** – Preserves log files when errors occur.
- **`PKGMGR=apt`** – Specifies the package manager for tracking system changes.
- **`PHALANX2_DIRTEST=1`** – Improves detection capabilities for specific rootkit families.
- **`WEB_CMD=""`** – Disables web-based updates to work around a known Debian bug.
- **`USE_LOCKING=1`** – Prevents concurrent scan instances that could cause conflicts.
- **`SHOW_SUMMARY_WARNINGS_NUMBER=1`** – Displays the total count of warnings in scan reports.

## Enabling Automated Daily Scans

Rkhunter includes a cron script for daily execution. Enable it by reconfiguring the package, which updates `/etc/default/rkhunter` to activate the scheduled task.

```bash
sudo dpkg-reconfigure rkhunter

```

Select "Yes" when prompted to enable the daily cron script. Alternatively, place a custom script in `/etc/cron.daily/` to control execution timing and reporting parameters.

## Validating Configuration and Updating the Database

Before running scans, verify configuration syntax and update the detection signatures to recognize the latest threats.

Validate the configuration files:

```bash
sudo rkhunter -C

```

Update the program and its database:

```bash
sudo rkhunter --versioncheck   # Check for latest program version

sudo rkhunter --update         # Download latest rootkit signatures

sudo rkhunter --propupd        # Store baseline hashes of current system files

```

Run `--propupd` after installing new packages or updating system binaries to prevent false positives in future scans.

## Executing Manual Rootkit Scans

Perform an immediate system scan using the `--check` flag. The command analyzes file hashes, searches for hidden processes, and checks for known rootkit signatures.

```bash
sudo rkhunter --check

```

Add `--quiet` to suppress non-essential output or `--sk` to skip known-safe files for faster execution. When `MAIL-ON-WARNING` is configured and the cron job is active, daily scans automatically email reports without manual intervention.

## Summary

- Install Rkhunter via `sudo apt install rkhunter` to deploy the binary to `/usr/bin/rkhunter` and configs under `/etc/`.
- Always backup [`/etc/rkhunter.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/rkhunter.conf) to `/etc/rkhunter.conf.local` before customizing settings.
- Enable critical options including `UPDATE_MIRRORS=1`, `MAIL-ON-WARNING=root`, and `USE_LOCKING=1` in the local configuration file.
- Validate syntax with `sudo rkhunter -C` before executing scans to prevent runtime errors.
- Maintain detection accuracy by running `--versioncheck`, `--update`, and `--propupd` regularly.
- Automate monitoring by enabling the daily cron job through `sudo dpkg-reconfigure rkhunter`.

## Frequently Asked Questions

### What is Rkhunter and how does it detect rootkits?

Rkhunter is a command-line scanner that identifies rootkits by comparing file hashes against a built-in database, scanning for hidden processes, and checking system binaries for suspicious strings. It operates entirely in userspace without kernel modules, making it compatible with most Linux distributions while remaining lightweight.

### Where does Rkhunter store its configuration files?

The primary configuration resides in [`/etc/rkhunter.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/rkhunter.conf), while local customizations should be placed in `/etc/rkhunter.conf.local` to survive package updates. Package-level defaults that control cron behavior are stored in `/etc/default/rkhunter`.

### How often should I update Rkhunter's signature database?

Update the database immediately after installation using `sudo rkhunter --update`, and run `sudo rkhunter --propupd` whenever you install new system packages or modify core binaries. Check for program updates monthly using `sudo rkhunter --versioncheck` to ensure you have the latest detection capabilities.

### Can Rkhunter send email alerts when it detects threats?

Yes, set `MAIL-ON-WARNING` to your administrative email address (such as `root`) in `/etc/rkhunter.conf.local`. When combined with the daily cron job enabled via `dpkg-reconfigure rkhunter`, the system automatically emails warning summaries without requiring manual monitoring.