Linux Rootkit (LD_PRELOAD, Hidden PID & LKM) Audit Builder (2026)

Generate zero-dependency Linux forensic one-liners to detect userland LD_PRELOAD/ld.so.preload shared-library hooks, unlinked /proc PID discrepancies, hidden Loadable Kernel Modules (LKM), eBPF tracepoint rootkits, and analyze suspicious terminal audit outputs.

Linux Rootkit (LD_PRELOAD, Hidden PID & LKM) Audit Builder — Interactive Console
Runs locally in your browser • Instant output
Linux Rootkit & Kernel/Userland Discrepancy Matrix
/proc/sys/kernel/tainted:
Userland LD_PRELOAD Hook (/etc/ld.so.preload)
Userland

Malicious shared object (.so) intercepts libc readdir() and accept() so ps, ls, and netstat hide rootkit files/ports (bdvl / Azazel / Jynx2).

$ ls -la /etc/ld.so.preload; env | grep LD_; grep -a "ld.so.preload" /lib/*/ld-*.so
LKM Kernel Module Unlinking (/proc/modules vs /sys/module)
Kernel LKM

Rootkit calls list_del(&THIS_MODULE->list) to vanish from lsmod and /proc/modules while leaving kobject remnants in /sys/module or /proc/kallsyms (Diamorphine / Reptile).

$ diff <(awk '{print $1}' /proc/modules | sort) <(ls /sys/module | sort); grep -E "diamorphine|reptile|sys_call_table" /proc/kallsyms
Hidden PID Discrepancy (/proc Brute-Force vs ps -ef)
Kernel LKM

Hooked getdents64() filters PID directories when listing /proc, but direct chdir('/proc/<PID>') or kill(pid, 0) reveals the hidden process.

$ for p in $(seq 1 65535); do [ -d "/proc/$p" ] && ! ps -p "$p" >/dev/null 2>&1 && echo "HIDDEN PID: $p ($(cat /proc/$p/comm 2>/dev/null))"; done
eBPF Tracepoint / XDP Rootkit Hooks (bpftool)
eBPF

Attacker attaches eBPF programs to raw_syscalls:sys_enter or bpf_probe_write_user to spoof /etc/shadow reads or drop C2 magic packets before iptables.

$ bpftool prog show; bpftool map show; sysctl kernel.unprivileged_bpf_disabled
Rogue Linux Capabilities & PAM Authentication Backdoor
Persistence

cap_setuid+ep granted to /usr/bin/python3 (invisible to SUID find) or backdoored /lib/security/pam_unix.so accepting a hardcoded master password.

$ getcap -r / 2>/dev/null; find / -perm -4000 -type f 2>/dev/null; debsums -s libpam-modules || rpm -V pam
Generated Live-Response Bash Forensic Script
#!/usr/bin/env bash
# ZeroUniverse Linux Rootkit, LD_PRELOAD & Syscall Forensic Live-Response Script
set -u
echo "=== [0] KERNEL TAINT & INTEGRITY CHECK ==="
cat /proc/sys/kernel/tainted

echo "=== [1] USERLAND LD_PRELOAD HOOK (/ETC/LD.SO.PRELOAD) ==="
ls -la /etc/ld.so.preload; env | grep LD_; grep -a "ld.so.preload" /lib/*/ld-*.so

echo "=== [2] LKM KERNEL MODULE UNLINKING (/PROC/MODULES VS /SYS/MODULE) ==="
diff <(awk '{print $1}' /proc/modules | sort) <(ls /sys/module | sort); grep -E "diamorphine|reptile|sys_call_table" /proc/kallsyms

echo "=== [3] HIDDEN PID DISCREPANCY (/PROC BRUTE-FORCE VS PS -EF) ==="
for p in $(seq 1 65535); do [ -d "/proc/$p" ] && ! ps -p "$p" >/dev/null 2>&1 && echo "HIDDEN PID: $p ($(cat /proc/$p/comm 2>/dev/null))"; done

echo "=== [4] EBPF TRACEPOINT / XDP ROOTKIT HOOKS (BPFTOOL) ==="
bpftool prog show; bpftool map show; sysctl kernel.unprivileged_bpf_disabled

echo "=== [5] ROGUE LINUX CAPABILITIES & PAM AUTHENTICATION BACKDOOR ==="
getcap -r / 2>/dev/null; find / -perm -4000 -type f 2>/dev/null; debsums -s libpam-modules || rpm -V pam
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![Linux Rootkit (LD_PRELOAD, Hidden PID & LKM) Audit Builder](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/linux-rootkit-ld-preload-syscall-auditor/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/linux-rootkit-ld-preload-syscall-auditor/">Linux Rootkit (LD_PRELOAD, Hidden PID & LKM) Audit Builder — ZerosUniverse</a>

2026 Quick-Reference Cheat Sheet & Benchmark Table: Linux Rootkit (LD_PRELOAD, Hidden PID & LKM) Audit Builder

Quick Answer & 2026 Technical Summary (linux rootkit detection commands ld_preload)Updated 2026 Standard

Standard Linux utilities like ls, ps, and top dynamically link against glibc (libc.so.6) and call C library functions like readdir() or readdir64() to read /proc and filesystem directories. By placing a malicious shared library (.so) in /etc/ld.so.preload or the LD_PRELOAD environment variable, the dynamic linker loads the rootkit's custom readdir() first, which filters out specific filenames, UIDs, or /proc/<PID> directories before returning results. Use this interactive linux rootkit detection commands ld_preload above to test detect ld_preload rootkit linux, hidden pid procfs vs kill brute force, and linux kernel module lkm rootkit hunter locally in your browser with zero server uploads.

Target Keyword Spec: linux rootkit detection commands ld_preload | Modules: Zero-Dependency Forensic Audit Script Generator • LD_PRELOAD & /etc/ld.so.preload Hook Inspector • Hidden PID Cross-View Discrepancy Analyzer
Primary Focus: linux rootkit detection commands ld_preload
Core Capability: detect ld_preload rootkit linux
Privacy Mode: 100% Client-Side (Zero Upload)
Technical Parameter / ModuleStandard / Keyword SpecArchitecture & Validation RuleOperational Use Case (2026)
Zero-Dependency Forensic Audit Script Generatordetect ld_preload rootkit linuxBuild copy-ready, read-only Bash audit scripts using busybox/static primiti...Compromised Linux VPS & Cloud Container Forensics
LD_PRELOAD & /etc/ld.so.preload Hook Inspectorhidden pid procfs vs kill brute forceAudit dynamic linker environment variables, /proc/*/maps shared object inje...Blue Team & DFIR Live-Response Playbooks
Hidden PID Cross-View Discrepancy Analyzerlinux kernel module lkm rootkit hunterCompare kill -0 PID signal sweeps against /proc/[0-9]* directory enumeratio...CTF & Red/Blue Lab Rootkit Dissection
Execution & Privacy Architecture100% Client-Side WebCrypto / JS Sandbox0 Bytes Sent to External ServersSafe for internal SOC & authorized lab artifacts
NIST SP 800-53 / OWASP AlignmentOWASP ASVS v4.0.3 / NIST CSF 2.0Deterministic Rule & Header VerificationMaps findings to actionable hardening controls
Cryptographic & Entropy StandardSHA-256 / AES-256-GCM / Argon2id≥ 128-bit Effective Security MarginMeets 2026 post-quantum & zero-trust baselines
In-Depth ZerosUniverse Tutorial

What is a Rootkit & How to Detect Kernel/Userland Rootkits

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use Linux Rootkit (LD_PRELOAD, Hidden PID & LKM) Audit Builder

01

Select Target Linux Threat Layers

Toggle audit modules for Userland Dynamic Linker (LD_PRELOAD), Hidden Process/Socket Enumeration, Loadable Kernel Modules (LKM), and eBPF/Kprobe hooks.

02

Copy & Run the Read-Only Forensic One-Liner

Copy the generated POSIX-compliant audit script (which avoids relying on potentially trojanized userland binaries) and run it on your target Linux host.

03

Paste Terminal Audit Output into the Forensic Analyzer

Paste your terminal output—or load a simulated Diamorphine LKM / Uncleared ld.so.preload compromise preset—to parse findings.

04

Follow Safe Neutralization & Recovery Commands

Review the flagged indicators (such as kernel taint bits 4096/12288 or hooked /etc/ld.so.preload paths) and execute the static busybox recovery steps.

Key Capabilities & Technical Architecture

Zero-Dependency Forensic Audit Script Generator

Build copy-ready, read-only Bash audit scripts using busybox/static primitives to bypass trojanized ps, ls, netstat, and lsof userland binaries.

LD_PRELOAD & /etc/ld.so.preload Hook Inspector

Audit dynamic linker environment variables, /proc/*/maps shared object injections, and libc readdir()/getdents64() symbol overrides used by userland rootkits like Jynx2 and Azazel.

Hidden PID Cross-View Discrepancy Analyzer

Compare kill -0 PID signal sweeps against /proc/[0-9]* directory enumeration and scheduler cgroup tasks to expose processes cloaked by getdents64 syscall hooking.

LKM, Syscall Table & eBPF Program Output Parser

Paste output from /proc/kallsyms, lsmod vs /sys/module, taint flags (/proc/sys/kernel/tainted), and bpftool prog list to automatically highlight rootkit indicators.

Practical Use Cases

Compromised Linux VPS & Cloud Container Forensics

Investigate servers exhibiting 100% CPU usage or outbound mining traffic where top, ps, and ss show zero suspicious processes due to userland or kernel hooking.

Blue Team & DFIR Live-Response Playbooks

Generate a single self-contained verification script for incident responders that checks userland dynamic linker integrity, SUID anomalies, and kernel taint state.

CTF & Red/Blue Lab Rootkit Dissection

Understand the exact mechanical difference between Ring-3 libc function hooking (LD_PRELOAD) and Ring-0 kernel VFS/ftrace/eBPF syscall hijacking.

Frequently Asked Questions (FAQs)

How does an LD_PRELOAD userland rootkit hide files and processes from ls and ps?+

Standard Linux utilities like ls, ps, and top dynamically link against glibc (libc.so.6) and call C library functions like readdir() or readdir64() to read /proc and filesystem directories. By placing a malicious shared library (.so) in /etc/ld.so.preload or the LD_PRELOAD environment variable, the dynamic linker loads the rootkit's custom readdir() first, which filters out specific filenames, UIDs, or /proc/<PID> directories before returning results.

Why can't you simply run 'rm /etc/ld.so.preload' if a userland rootkit hooks unlink()?+

Wait—if a rootkit intercepts open(), stat(), and unlink() via /etc/ld.so.preload, running dynamically linked commands like rm or cat will also be intercepted and told the file doesn't exist! To bypass this, defenders use a statically compiled binary (like busybox or sln) that makes raw kernel syscalls directly without loading ld-linux.so.

How do Loadable Kernel Module (LKM) rootkits like Diamorphine or Reptile hide themselves from lsmod?+

In Ring-0 kernel space, an LKM rootkit calls list_del(&THIS_MODULE->list) and kobject_del(&THIS_MODULE->mkobj.kobj) during initialization to unlink itself from the kernel's internal module linked list and /sys/module sysfs tree, making it invisible to lsmod and /proc/modules while its hooked syscalls (like sys_getdents64 and sys_kill) remain active in kernel memory.

What does a Linux kernel taint value of 4096 or 12288 in /proc/sys/kernel/tainted mean?+

The Linux kernel maintains a bitmask in /proc/sys/kernel/tainted. Bit 12 (value 4096, flag 'O') indicates an out-of-tree module was loaded, and Bit 13 (value 8192, flag 'E') indicates an unsigned module was loaded. A combined value of 12288 (4096 + 8192) when lsmod shows no third-party modules is a strong indicator of a hidden LKM rootkit.

How do modern eBPF rootkits work without loading a kernel module?+

On Linux kernels 5.x+, privileged eBPF programs can use bpf_probe_write_user() inside tracepoints or kprobes attached to sys_enter_getdents64 / sys_exit_getdents64 to overwrite directory buffer entries in user space on the fly. Auditing with 'bpftool prog show' and 'bpftool map show' exposes active eBPF hooks.