Installing Rkhunter (Rootkit Hunter) in RHEL, CentOS and Fedora

cd /tmp
# wget

# tar -xvf rkhunter-1.4.0.tar.gz
# cd rkhunter-1.4.0
# ./ --layout default --install

# /usr/local/bin/rkhunter --update
# /usr/local/bin/rkhunter --propupd

nano /etc/cron.daily/

Add the following lines of code to it and replace “YourServerNameHere” with your “Server Name” and “” with your “Email Id“.

/usr/local/bin/rkhunter --versioncheck
/usr/local/bin/rkhunter --update
/usr/local/bin/rkhunter --cronjob --report-warnings-only
) | /bin/mail -s 'rkhunter Daily Run (servername)'

Set execute permission on the

# chmod 755 /etc/cron.daily/

To scan the entire file system, run the Rkhunter as a root user.

# rkhunter --check

The above command generates log file under /var/log/rkhunter.log with the checks results made by Rkhunter. For more information and options please run the following command.

# rkhunter --help

