awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
rfxn avatar

rfxn/linux-malware-detect

0
View on GitHub↗
1,456 stars·247 forks·Shell·GPL-2.0·0 viewswww.rfxn.com/projects/linux-malware-detect↗

Linux Malware Detect

Linux Malware Detect is a security platform designed for Linux server environments to identify and isolate malicious files. It functions as a multi-engine scanner that utilizes signature-based detection, heuristic analysis, and pattern matching to maintain system integrity. The tool provides automated auditing and real-time monitoring to detect unauthorized modifications as they occur.

The system distinguishes itself through kernel-level event monitoring, which triggers immediate scans upon file changes, and checkpoint-based scan resumption, which allows long-running operations to pause and restart without redundant processing. It manages threat containment by moving suspicious files into isolated quarantine storage, preventing execution while preserving them for forensic review.

Beyond core detection, the platform includes comprehensive incident response capabilities, such as asynchronous alert dispatching across multiple communication channels and the ability to export scan summaries for external monitoring. It supports modular threat feed synchronization to ensure the local detection engine remains updated against emerging threats.

Features

  • Linux Malware Scanners - Scans Linux filesystems for malicious content using multiple detection engines to identify and isolate threats.
  • Inotify-Based Watchers - Hooks into kernel-level filesystem notifications to trigger immediate security scans upon file modifications.
  • Malware Scanning - Identifies malicious files by comparing system contents against a database of known threat signatures and heuristic patterns.
  • Malware Quarantines - Isolates suspicious files into a restricted directory structure to prevent execution while preserving them for forensic review.
  • Real-Time File Scanners - Monitors filesystem activity in real-time using kernel events to detect and scan new or modified files for malicious content.
  • Linux Security Tools - Provides a system-level threat detection platform with automated scanning, file quarantine, and multi-channel alerting.
  • Feed Integrations - Synchronizes external threat signature databases to keep the local detection engine updated against emerging security threats.
  • Automated Audit Schedulers - Schedules recurring system-wide security audits and generates detailed reports to maintain system integrity.
  • Security Scan Schedulers - Automates system security checks on a recurring schedule to identify and isolate malicious files.
  • Scan State Persistence - Maintains persistent state records during filesystem traversals to allow long-running scans to resume without redundant processing.
  • YARA-Based Scanning - Leverages YARA rules and MD5 signatures to scan Linux filesystems for known threats and unauthorized modifications.
  • Threat-Based Scanning - Inspects files during transit or upload to identify malicious content using threat-based scanning patterns.
  • Storage Isolation - Moves suspicious files into restricted directory structures to prevent execution while preserving them for forensic review.
  • File Content Signature Matching - Executes sequential detection passes using hash comparisons and pattern matching to identify malicious code within files.
  • Quarantine Management - Isolates suspicious files into secure directories to prevent execution while providing tools for review and restoration.
  • Alert Notification Systems - Dispatches automated notifications about detected threats to messaging platforms and logging systems.
  • Alerting and Incident Management - Dispatches automated notifications about detected threats to facilitate rapid incident response.

Star history

Star history chart for rfxn/linux-malware-detectStar history chart for rfxn/linux-malware-detect

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Linux Malware Detect

Similar open-source projects, ranked by how many features they share with Linux Malware Detect.
  • cisco-talos/clamavCisco-Talos avatar

    Cisco-Talos/clamav

    6,869View on GitHub↗

    ClamAV - Documentation is here: https://docs.clamav.net

    Cantivirusclamavgplv2
    View on GitHub↗6,869
  • velocidex/velociraptorVelocidex avatar

    Velocidex/velociraptor

    3,769View on GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    View on GitHub↗3,769
  • neo23x0/lokiNeo23x0 avatar

    Neo23x0/Loki

    3,763View on GitHub↗

    Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a YARA-based indicator of compromise scanner designed to identify malicious persistence mechanisms, web shells, and unauthorized administration tools across local and remote systems. The project distinguishes itself by integrating multi-source threat intelligence, allowing for the loading of custom signature sets and encrypted indicators. It combines hash-based artifact detection with YARA rule execution to scan files, process memory, and registry hives for known malicious byte seq

    Python
    View on GitHub↗3,763
  • six2dez/reconftwsix2dez avatar

    six2dez/reconftw

    7,226View on GitHub↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    Shellbug-bountybugbountybugbounty-tool
    View on GitHub↗7,226
See all 30 alternatives to Linux Malware Detect→

Frequently asked questions

What does rfxn/linux-malware-detect do?

Linux Malware Detect is a security platform designed for Linux server environments to identify and isolate malicious files. It functions as a multi-engine scanner that utilizes signature-based detection, heuristic analysis, and pattern matching to maintain system integrity. The tool provides automated auditing and real-time monitoring to detect unauthorized modifications as they occur.

What are the main features of rfxn/linux-malware-detect?

The main features of rfxn/linux-malware-detect are: Linux Malware Scanners, Inotify-Based Watchers, Malware Scanning, Malware Quarantines, Real-Time File Scanners, Linux Security Tools, Feed Integrations, Automated Audit Schedulers.

What are some open-source alternatives to rfxn/linux-malware-detect?

Open-source alternatives to rfxn/linux-malware-detect include: cisco-talos/clamav — ClamAV - Documentation is here: https://docs.clamav.net. velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… neo23x0/loki — Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a… six2dez/reconftw — reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the… projectdiscovery/subfinder — Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It… cisco-talos/clamav-devel — ClamAV is an open-source antivirus engine and malware detection scanner. It identifies trojans, viruses, and other…

Curated searches featuring Linux Malware Detect

Hand-picked collections where Linux Malware Detect appears.
  • Open Source Intrusion Detection Systems
  • YARA Malware Detection Rules
  • open-source antivirus / malware scanner