This group of tools checks for the presence of techniques commonly used by rootkits in the system and provides detailed information. They are very useful for behavioral analysis to confirm that the sample has been loaded properly. Additionally, they can be used to determine the functionality of the sample relatively quickly. Some of the most popular tools are as follows:
- GMER: This powerful tool supports multiple rootkit patterns and provides relatively detailed technical information. It is able to search for various hidden artifacts, such as processes, services, files, registry keys, and more. Additionally, it features the rootkit removal tool.
- RootkitRevealer: This is another advanced rootkit detection tool—this time from Sysinternals. Unlike GMER, its output is less technical and it hasn't been updated for a while.
Other discontinued rootkit detection tools include Rootkit Unhooker, DarkSpy, and IceSword.
Apart from these, there are multiple rootkit...