Re: ossec hit: Hidden process (rootkit)

2014-09-23 Thread List Monkey
Brandon, The ossec-rootcheck is not present on my install (has it been deprecated?) I am able to use the agent-control to force a complete run. It runs without error. Arne On 23. sep. 2014 02:29, Brandon Vincent wrote: > On Mon, Sep 22, 2014 at 2:10 AM, List Monkey wrote: >> Any other

ossec hit: Hidden process (rootkit)

2014-09-22 Thread List Monkey
I'm running freebsd as an vm. I recently got a hit from the ossec agent: OSSEC HIDS Notification. 2014 Aug 28 03:01:34 Received From: (host) xxx.xxx.xxx.xxx->rootcheck Rule: 510 fired (level 7) -> "Host-based anomaly detection event (rootcheck)." Portion of the log(s): Process '9990' hidden from