使用 Volatility3 Linux 插件(check_syscall、lsmod、hidden_modules)分析 Linux 内存转储,结合 rkhunter 系统扫描和 /proc 与 /sys 差异分析,检测 hooked syscall、隐藏内核模块和被篡改的系统结构,以识别内核级 rootkit。
$npx -y skills add killvxk/cybersecurity-skills-zh --skill analyzing-linux-kernel-rootkitsInstalls into the current project.
Run `npx skills use "https://github.com/killvxk/cybersecurity-skills-zh" --skill "killvxk/cybersecurity-skills-zh/analyzing-linux-kernel-rootkits"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/killvxk/cybersecurity-skills-zh" that are relevant to the current task. Run `npx skills add "https://github.com/killvxk/cybersecurity-skills-zh"` and select the relevant skills, then follow their instructions.