How to Use Rkhunter for Rootkit Detection in Linux: Complete Setup Guide
Rkhunter (Rootkit Hunter) is a lightweight command-line scanner that detects rootkits, backdoors, and suspicious files by comparing file hashes against a built-in database and verifying system binaries without requiring kernel modules.
Securing a Linux server requires proactive malware detection and integrity monitoring. According to the imthenachoman/How-To-Secure-A-Linux-Server repository, implementing Rkhunter for rootkit detection in Linux provides a robust defense layer that scans for hidden processes, suspicious strings, and compromised system files. This guide walks through the complete installation, configuration, and maintenance workflow based on the repository's hardening recommendations.
Installing Rkhunter on Linux
Rkhunter is packaged for most Debian-based distributions and installs the main binary to /usr/bin/rkhunter alongside default configuration files under /etc/.
sudo apt install rkhunter
This creates the primary configuration file at /etc/rkhunter.conf and package defaults at /etc/default/rkhunter.
Preserving and Configuring Rkhunter Settings
Backing Up Original Configuration Files
Before modifying any settings, preserve the vendor-provided configurations to enable rollback if needed. The repository recommends timestamped backups for the defaults file and a .local copy for the main configuration.
# Backup the package defaults file
sudo cp -p /etc/default/rkhunter /etc/default/rkhunter-COPY-$(date +"%Y%m%d%H%M%S")
# Create a local configuration file for custom settings
sudo cp -p /etc/rkhunter.conf /etc/rkhunter.conf.local
Creating Local Configuration Overrides
Instead of editing /etc/rkhunter.conf directly, place custom settings in /etc/rkhunter.conf.local. This ensures vendor updates do not overwrite your changes while enabling tailored security policies.
Add the following key parameters to /etc/rkhunter.conf.local:
UPDATE_MIRRORS=1– Enables automatic mirror updates for signature files.MIRRORS_MODE=0– Uses the default mirror selection algorithm.MAIL-ON-WARNING=root– Routes email alerts to the system administrator.COPY_LOG_ON_ERROR=1– Preserves log files when errors occur.PKGMGR=apt– Specifies the package manager for tracking system changes.PHALANX2_DIRTEST=1– Improves detection capabilities for specific rootkit families.WEB_CMD=""– Disables web-based updates to work around a known Debian bug.USE_LOCKING=1– Prevents concurrent scan instances that could cause conflicts.SHOW_SUMMARY_WARNINGS_NUMBER=1– Displays the total count of warnings in scan reports.
Enabling Automated Daily Scans
Rkhunter includes a cron script for daily execution. Enable it by reconfiguring the package, which updates /etc/default/rkhunter to activate the scheduled task.
sudo dpkg-reconfigure rkhunter
Select "Yes" when prompted to enable the daily cron script. Alternatively, place a custom script in /etc/cron.daily/ to control execution timing and reporting parameters.
Validating Configuration and Updating the Database
Before running scans, verify configuration syntax and update the detection signatures to recognize the latest threats.
Validate the configuration files:
sudo rkhunter -C
Update the program and its database:
sudo rkhunter --versioncheck # Check for latest program version
sudo rkhunter --update # Download latest rootkit signatures
sudo rkhunter --propupd # Store baseline hashes of current system files
Run --propupd after installing new packages or updating system binaries to prevent false positives in future scans.
Executing Manual Rootkit Scans
Perform an immediate system scan using the --check flag. The command analyzes file hashes, searches for hidden processes, and checks for known rootkit signatures.
sudo rkhunter --check
Add --quiet to suppress non-essential output or --sk to skip known-safe files for faster execution. When MAIL-ON-WARNING is configured and the cron job is active, daily scans automatically email reports without manual intervention.
Summary
- Install Rkhunter via
sudo apt install rkhunterto deploy the binary to/usr/bin/rkhunterand configs under/etc/. - Always backup
/etc/rkhunter.confto/etc/rkhunter.conf.localbefore customizing settings. - Enable critical options including
UPDATE_MIRRORS=1,MAIL-ON-WARNING=root, andUSE_LOCKING=1in the local configuration file. - Validate syntax with
sudo rkhunter -Cbefore executing scans to prevent runtime errors. - Maintain detection accuracy by running
--versioncheck,--update, and--propupdregularly. - Automate monitoring by enabling the daily cron job through
sudo dpkg-reconfigure rkhunter.
Frequently Asked Questions
What is Rkhunter and how does it detect rootkits?
Rkhunter is a command-line scanner that identifies rootkits by comparing file hashes against a built-in database, scanning for hidden processes, and checking system binaries for suspicious strings. It operates entirely in userspace without kernel modules, making it compatible with most Linux distributions while remaining lightweight.
Where does Rkhunter store its configuration files?
The primary configuration resides in /etc/rkhunter.conf, while local customizations should be placed in /etc/rkhunter.conf.local to survive package updates. Package-level defaults that control cron behavior are stored in /etc/default/rkhunter.
How often should I update Rkhunter's signature database?
Update the database immediately after installation using sudo rkhunter --update, and run sudo rkhunter --propupd whenever you install new system packages or modify core binaries. Check for program updates monthly using sudo rkhunter --versioncheck to ensure you have the latest detection capabilities.
Can Rkhunter send email alerts when it detects threats?
Yes, set MAIL-ON-WARNING to your administrative email address (such as root) in /etc/rkhunter.conf.local. When combined with the daily cron job enabled via dpkg-reconfigure rkhunter, the system automatically emails warning summaries without requiring manual monitoring.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →