{"id":13840579,"url":"https://github.com/dgoulet/kjackal","last_synced_at":"2025-07-11T09:32:21.675Z","repository":{"id":2482582,"uuid":"3456011","full_name":"dgoulet/kjackal","owner":"dgoulet","description":"Linux Rootkit Scanner","archived":false,"fork":false,"pushed_at":"2022-01-24T12:40:12.000Z","size":215,"stargazers_count":84,"open_issues_count":2,"forks_count":32,"subscribers_count":11,"default_branch":"master","last_synced_at":"2024-08-05T17:25:17.905Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/dgoulet.png","metadata":{"files":{"readme":"README","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2012-02-16T01:42:58.000Z","updated_at":"2023-11-07T18:18:07.000Z","dependencies_parsed_at":"2022-09-09T06:23:04.293Z","dependency_job_id":null,"html_url":"https://github.com/dgoulet/kjackal","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dgoulet%2Fkjackal","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dgoulet%2Fkjackal/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dgoulet%2Fkjackal/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dgoulet%2Fkjackal/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/dgoulet","download_url":"https://codeload.github.com/dgoulet/kjackal/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225712505,"owners_count":17512414,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:00:50.585Z","updated_at":"2024-11-21T10:30:26.383Z","avatar_url":"https://github.com/dgoulet.png","language":"C","funding_links":[],"categories":["C"],"sub_categories":[],"readme":"Kjackal project\n----------------\n\nNOTICE:\n\nIn no situation will we be liable for any loss or damage including without\nlimitation, indirect or consequential loss or damage, or any loss or damage\nwhatsoever arising from loss of data or profits arising out of, or in\nconnection with, the use of the data in this repository.\n\nThis is a kernel module so like any other kernel module things can go bad. It\nwill NOT destroy any data or corrupt your hard drive. At worst, you'll get a\nkernel panic and you'll have to reboot. If this happens, PLEASE report it :).\n\nFeel free to check the code, there is NO hidden backdoors or any shenanigans to\ninstall any undesired software on your computer.\n\nABOUT:\n\nKjackal is a one time Linux kernel module rootkit scanner. It is *not* a\nrootkit AV or any IPS bimbo-blabla system. The purpose of kjackal is to quickly\nscan the Linux kernel for rootkit(s).\n\nSo commonly, a kernel module rootkit, once loaded, will hijack the syscall\ntable, the proc fileystem (to hide itself) and TCP4 operations to hide\nbackdoors' port.\n\nKjackal uses multiple methods to find hidden modules. Here is the list:\n\n1) Syscall hijack detection.\n\nThe primary technique is to iterate over the syscall table and test\nevery address to see if it is in the core kernel text section where it's\nsupposed to be. If yes, we'll check for a module \"hosting\" this address.\n\n2) TCP IPv4 seq_ops hijack detection.\n\nThis technique is often used to hide ports or any sensitive information.\nThe 'seq_ops.show' is checked here to the core kernel text address space.\n\n3) /proc filesystem hijack detection.\n\nCheck the readdir ops of /proc.\n\n4) Search for hidden modules\n\nSearch for each *hidden* module which tries to remove itself from existence.\nkjackal still has some card up his sleeve ;) to get them.\n\nREQUIREMENTS:\n\nTested on 2.6.32 up to 3.15.0 However, it might work for an older kernel.\nPlease report if you succeed.\n\n- Linux Kernel Headers 2.6.32 or later\n\n  * Debian: sudo apt-get install linux-headers\n  * Redhat: sudo yum install kernel-headers\n  * Arch: sudo pacman -S linux-headers\n  * Gentoo: sudo emerge linux-headers\n\nCOMPILE:\n\n# make\n\nUSAGE:\n\n# insmod kjackal.ko\n# dmesg\n\nKjackal prints the report in dmesg.\n\n# rmmod kjackal\n\nTESTS:\n\nThe tests/ directory contains three simple kernel modules to test kjackal.\nPlease read carefully the comments in the .c file before loading one of them.\n\nWHAT'S NEXT:\n\nSo time for the fun part.\n\n*IF* kjackal detects a rogue kernel module, please report it so we can\ninvestigate it! There is a feature in src/module.c called \"module_dump_memory\"\nwhich can be used to dump the entire module memory if detected. It will be\ncreated in /tmp/rootkit-module.dump. Enable this and we'll have fun after that.\n\nAlso, PLEASE contribute your ideas/comments/code/bugs to this project to make\nit better and more efficient at finding kernel module rookits. Please send me\nany rootkit code you came upon to study them or any commercial one would be\nreally nice also.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdgoulet%2Fkjackal","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fdgoulet%2Fkjackal","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdgoulet%2Fkjackal/lists"}