Rootcheck is an open source rootkit detection software.

Installation

$ wget http://www.ossec.net/rootcheck/files/rootcheck-1.5.tar.gz

$ tar -zxvf rootcheck-1.5.tar.gz

$ cd rootcheck-1.5

$ make all

Usage

$ ./ossec-rootcheck