chkrootkit
is a tool to locally check for signs of a rootkit.
chkrootkit has been tested on: Linux 2.0.x, 2.2.x, 2.4.x and 2.6.x
FreeBSD 2.2.x, 3.x, 4.x and 5.x
OpenBSD 2.x and 3.x.
NetBSD 1.6.x
Solaris 2.5.1, 2.6, 8.0 and 9.0
HP-UX 11
Tru64
BSDI and Mac OS X.
Latest features added ( 10th Oct 2006 ):
new test: crontab
new rootkits detected: Enye LKM, Lupper.Worm, shv5
more ports added to the bindshell test
some minor bug fixes