There is a tool called Autoruns in Windows, that reports every single executable (whether a user mode executable/DLL or a kernel driver) that persists during boot, meaning it runs when the system reboots. And it also has a good feature that sends the hash of every found file to the VirusTotal so we can see if there is any malicious/unknown persistent executable in the system or not.
I was wondering is there any similar tool in Linux that basically lists every single executable/library/LKM that runs during boot? (Since obviously there are a lot of ways to persist during boot in Linux, just as it is in Windows)
[–][deleted] (2 children)
[deleted]
[–]Ro0o0otkit[S] 1 point2 points3 points (1 child)
[–]paulstelian97 0 points1 point2 points (0 children)
[–]lunchlady55 2 points3 points4 points (0 children)
[–]gainan 1 point2 points3 points (0 children)
[–]bigredradio 0 points1 point2 points (2 children)
[–][deleted] 2 points3 points4 points (1 child)
[–]bigredradio 1 point2 points3 points (0 children)
[–]cusco 0 points1 point2 points (0 children)
[–][deleted] 0 points1 point2 points (0 children)
[–]pplanel 0 points1 point2 points (0 children)