Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
security checks — linux security checks | Kitploit
Tools/GitLabGitLab/abdom.seada/security-checks
Defensive ToolsMemory ForensicsVulnerability AnalysisNetwork ForensicsConfiguration AuditingForensicsMalware AnalysisDigital ForensicsIntrusion DetectionIncident ResponseLog Analysis
196 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitLab
abdom.seada/security-checks

security checks

linux security checks

View Repository
Share

🔍 Miner Hunter

Crypto-miner detection, removal, and hardening toolkit for Linux servers.

Built from real-world incident response — detects miners that hide from ps, top, htop, and btop using rootkit techniques.


📦 Installation

git clone https://gitlab.com/abdom.seada/security-checks.git
cd security-checks
sudo bash setup.sh

🔀 Branch: master — This toolkit lives on the master branch. Other security scripts may be added on separate branches in the future.


⚙️ Setup

⚠️ Run setup.sh once right after cloning — skipping this is the #1 cause of errors.

sudo bash setup.sh

setup.sh handles everything automatically:

StepWhat it does
✅ Permissionschmod +x on miner-hunter and all lib/*.sh scripts
✅ DirectoriesCreates /var/log/miner_hunter/ and /var/lib/miner_hunter/ (root-only, 700)
✅ DependenciesChecks perf, mpstat, iptables, fail2ban, bc, strings — auto-installs missing ones
✅ Self-testRuns ./miner-hunter --version to confirm everything is wired up correctly

Expected output when setup succeeds:

✅ Setup complete — all checks passed!

  Next steps:
    sudo ./miner-hunter scan        # Safe read-only scan
    sudo ./miner-hunter full        # Scan → Kill → Harden

💡 Why is this needed? Linux won't execute a file unless it has the +x flag. Git and SCP transfers strip this. setup.sh fixes all files in one shot — including the lib/ modules the main script depends on.


🚀 Quick Start

sudo ./miner-hunter scan            # ✅ Safe — read-only, zero changes
sudo ./miner-hunter full            # ⚠️  Full pipeline: Scan → Kill → Harden
sudo ./miner-hunter scan --dry-run  # 👁️  Preview mode — shows what would happen

📋 Commands & Options

Commands

CommandDescriptionChanges system?
scanFull detection scan — hidden processes, CPU, network, persistence✅ No
killKill identified miners, block pool IPs, remove artifacts⚠️ Yes
hardenPost-incident hardening — SSH, firewall, watchdog, integrity baseline⚠️ Yes
fullRuns scan → kill → harden with confirmation prompts between phases⚠️ Yes
reportDisplay the most recent scan report✅ No

Options

OptionDescription
-d, --dry-runPreview all actions without making any changes
-e, --evidence DIRSave evidence to a custom directory instead of /root/miner_evidence_*
-h, --helpShow help
-v, --versionShow version

🎭 Case Scenarios

Real-world situations and exactly what to run in each one.


🔴 Scenario 1 — "My server CPU is at 100% but top shows nothing"

This is the classic rootkit symptom. The miner is hiding from userspace tools but cannot hide from hardware performance counters.

# Step 1: Run a safe scan first — confirm what's there before touching anything
sudo ./miner-hunter scan

What you'll see if a miner is present:

🚨 [CRITICAL]  CPU anomaly: 97% user CPU but top shows max 2% per process
🚨 [CRITICAL]  perf detected 4 hidden threads consuming ~94% total CPU
🚨 [CRITICAL]  Active connection to 185.x.x.x:9200 (known mining port)
🚨 [CRITICAL]  Fake kernel thread PID=3421 NAME=[kworker/0:1] EXE=/tmp/.x/miner
# Step 2: Kill the miner and block its pool
sudo ./miner-hunter kill

# Step 3: Harden the server so it can't come back
sudo ./miner-hunter harden

🟡 Scenario 2 — "I think I was hacked but I'm not sure"

You noticed something suspicious — unusual outbound traffic, a cron job you didn't create, a process with a weird name — but you're not certain.

# Run a full scan — completely safe, read-only, zero changes
sudo ./miner-hunter scan

# Then read the structured report
sudo ./miner-hunter report

The report at /root/miner_evidence_*/report.txt categorizes every finding by severity:

  • [CRITICAL] entries → proceed to kill immediately
  • [WARNING] entries → review manually before acting
  • Empty report → server appears clean

🟠 Scenario 3 — "I killed the miner manually but it keeps coming back"

The miner has a persistence mechanism — a cron job, systemd service, PM2 entry, or shell profile backdoor that respawns it after you kill it.

sudo ./miner-hunter scan

Look for these in the output:

⚠️  [WARN]     Suspicious cron entry: * * * * * /tmp/.x/update
🚨 [CRITICAL]  Malicious systemd service: /etc/systemd/system/update-check.service
🚨 [CRITICAL]  PM2 process 'app-worker' has 8432 restarts — likely miner respawn loop
🚨 [CRITICAL]  Shell profile backdoor detected in /root/.bashrc
# kill removes ALL persistence artifacts — not just the running process
sudo ./miner-hunter kill

# Then harden to install the watchdog so you're alerted if anything respawns
sudo ./miner-hunter harden

💡 After kill, the watchdog cron runs every 5 minutes and logs to /var/log/miner_hunter/watchdog_alerts.log — you'll know immediately if something comes back.


🔵 Scenario 4 — "I want to harden a fresh server before anything happens"

Proactive hardening before deploying — no miner, no incident, just locking things down.

# Run harden standalone — no scan or kill needed
sudo ./miner-hunter harden

This will:

  • Audit your SSH config and print the recommended settings
  • Verify fail2ban is active with an sshd jail
  • Create a /usr/bin integrity baseline (MD5 checksums — so you can detect tampered binaries later)
  • Install a cron watchdog that checks every 5 minutes for miner indicators
  • Persist any existing iptables rules across reboots via a systemd service

⚫ Scenario 5 — "The miner survived the kill — CPU is still high"

After kill, the verify step reports the miner may still be running:

⚠️  MINER MAY HAVE RESPAWNED
CPU: 89% | Mining conns: 1
Firewall blocks are in place — miner can't reach pool
Consider a REBOOT or OS REINSTALL
# 1. Firewall blocks are already in place — miner CANNOT reach its pool
#    Confirm blocks are active:
iptables -L OUTPUT -n | grep DROP

# 2. Run a second scan to see what survived
sudo ./miner-hunter scan

# 3. Check for a kernel module rootkit hiding the process
lsmod | grep -iE 'diamorphine|reptile|kovid|rootkit'

# 4. Non-zero taint = out-of-tree kernel modules loaded (rootkit indicator)
cat /proc/sys/kernel/tainted

If the kernel taint value is non-zero or a known rootkit module appears — the miner has kernel-level control. The safest path at this point is a full OS reinstall from a known-clean snapshot.


🟣 Scenario 6 — "I want ongoing monitoring without running scans manually"

After harden, the watchdog cron is already installed. Here's how to work with it:

# Watch the alert log in real time
tail -f /var/log/miner_hunter/watchdog_alerts.log

# Confirm the watchdog cron job is registered
cat /etc/cron.d/miner-watchdog

# Check for /usr/bin binary changes since your baseline was taken
md5sum --check /var/lib/miner_hunter/usrbin_baseline.md5 --quiet

Any output from the last command means a system binary was modified after your baseline — investigate immediately.


🔬 What It Detects

Hidden Process Detection

TechniqueWhat it catches
/proc vs ps comparisonProcesses invisible to userspace tools
LD_PRELOAD hijackingMalicious shared libraries hooking libc to hide processes
Kernel module rootkitsDiamorphine, Reptile, Kovid, and other known rootkits
Fake kernel threadsMiners masquerading as [kworker], [kthreadd], [kswapd]
Modified system binariesReplaced ps, top, ls, ss, netstat

CPU Profiling

Download Tool