StMichael LKM
Platforms:
Linux
Categories:
Auditing,
Backdoors
Version: v0.11
URL: http://www.sourceforge.net/projects/stjude
StMichael, is a LKM that detect sand divert attempts to install a kernel-module backdoor into a running linux system. This is done by monitoring the init_module and delete_module process for changes key kernel areas.

Mark[@]wwjh[dot]net
St Michael version 0.12 is due out within the next month or so,
regards,
Mark ...
[ more ]