Malware Scanning on Linux: ClamAV, rkhunter, and Lynis Compared
“Linux antivirus” usually means one of three quite different tools, and running the wrong one gives a false sense of security. This guide explains what ClamAV, rkhunter, chkrootkit, and Lynis each do, when they are worth running, and how to interpret their output.
First, some perspective from our article on Linux malware myths: most compromises of Linux systems come from weak credentials, unpatched services, and exposed admin panels, not from a virus a scanner would catch. Patching, SSH hardening, and a firewall do far more than any scanner.
Three different jobs
| Tool | What it does | Detects |
|---|---|---|
| ClamAV | Signature-based file scanner | Known malware in files, including Windows malware and phishing documents |
| rkhunter / chkrootkit | Rootkit and integrity checkers | Known rootkits, changed system binaries, suspicious files and settings |
| Lynis | Security auditor | Configuration weaknesses, missing hardening |
ClamAV: scanning files
ClamAV is an open source antivirus engine with a regularly updated signature database. Its strength is scanning files that pass through a system: email attachments on a mail server, uploads to a file share, downloads. It catches plenty of Windows malware, which matters if your Linux server hands files to Windows users.
sudo apt install clamav clamav-daemon # Debian / Ubuntu
sudo dnf install clamav clamav-update # Fedora
sudo pacman -S clamav # Arch
sudo freshclam # update signatures (often runs as a service)
clamscan -r --infected ~/Downloads # scan, show only infected files
clamscan loads the whole signature database every run, which is slow. For repeated scans, run the clamd daemon and use clamdscan, which talks to it:
sudo systemctl enable --now clamav-daemon # name varies by distro
clamdscan --multiscan --fdpass /srv/uploads
Do not let ClamAV delete files automatically at first. Use --move=/var/quarantine or just report, and review what it flags; false positives happen.
For real-time scanning of a directory, ClamAV’s on-access scanner (clamonacc) watches files as they are opened, using the kernel’s fanotify interface. It costs CPU and is mostly worthwhile on file servers.
rkhunter and chkrootkit: looking for rootkits
A rootkit hides an attacker’s presence by replacing system tools or loading kernel code, so that ps, ls, and netstat lie. These tools look for traces of known rootkits and for suspicious changes.
rkhunter
rkhunter (Rootkit Hunter) checks for known rootkits, but its most useful feature is a baseline: it records hashes and properties of important system binaries, then reports when they change.
sudo apt install rkhunter
sudo rkhunter --update # update data files
sudo rkhunter --propupd # record the current system as the baseline
sudo rkhunter --check --sk # run checks, skip keypresses
The catch: legitimate updates change binaries too. After every package update, rkhunter warns until you refresh the baseline with --propupd. Do that only after updates from trusted sources; otherwise you are telling it to accept whatever changed. On Debian and Ubuntu, setting APT_AUTOGEN="true" in /etc/default/rkhunter refreshes it automatically after apt runs.
Common false positives include scripts replacing binaries (some distributions ship egrep or which as scripts), hidden files in /dev that are actually legitimate, and SSH root login warnings. Investigate each once, then whitelist it in /etc/rkhunter.conf if it is expected.
chkrootkit
chkrootkit checks for known rootkit signatures and anomalies without a baseline:
sudo apt install chkrootkit
sudo chkrootkit
It is quick, and running it alongside rkhunter catches things each misses. Read “INFECTED” results carefully; some long-standing checks have known false positives on modern systems.
Lynis: auditing configuration
Lynis is not a scanner at all. It is a security audit: it checks hundreds of settings against hardening best practices and tells you what to improve.
sudo apt install lynis # or download the latest from the project for newer tests
sudo lynis audit system
The output groups findings into warnings and suggestions, each with a test ID, and ends with a hardening index. Typical suggestions: SSH settings, password policies, missing auditd, file permissions, kernel parameters you can set with sysctl, and services you could disable.
Do not chase a perfect score blindly; some suggestions do not fit every system. But on a new server, a Lynis run is one of the fastest ways to find the hardening steps you skipped. Pair it with our new server first steps and Linux security best practices. For a self-hosted page about Lynis, see Lynis.
Scheduling scans
Run them on a schedule and get the results mailed to you:
# /etc/cron.d/security-scans
30 3 * * 0 root /usr/bin/rkhunter --cronjob --report-warnings-only
0 4 * * 0 root /usr/bin/lynis audit system --cronjob > /var/log/lynis-weekly.log
A systemd timer works equally well and logs to the journal. To have cron output emailed, see sending mail from a server with msmtp.
The limit: you cannot trust a compromised system
A capable attacker with root, especially one running a kernel rootkit, controls what the system reports, including to these tools. A clean scan on a system you already suspect is weak evidence.
For a trustworthy check, boot from clean live media and scan the disk offline. And if you confirm a root-level compromise, the safe response is to rebuild from known-good media and restore data from backups taken before the compromise, not to clean it in place.
Much better than detection is prevention: keeping Linux updated, Fail2ban or CrowdSec on exposed services, and file integrity monitoring with auditd.
Frequently Asked Questions
Do I need antivirus on Linux?
On a typical desktop that installs software from distribution repositories and Flathub, a traditional antivirus adds little. Scanning makes sense on mail servers and file servers that pass files to Windows users, on systems that must meet compliance requirements, and as one input when investigating a suspected compromise.
What does ClamAV actually detect?
ClamAV detects known malware by signature, including Windows malware, malicious documents, phishing attachments, and some Linux malware. It is best at scanning files passing through a system, such as email attachments and uploads, rather than detecting an active intrusion.
What is the difference between rkhunter and chkrootkit?
Both look for signs of known rootkits and suspicious system changes. rkhunter also keeps a database of file hashes and properties so it can report when system binaries change, while chkrootkit checks for known rootkit signatures and anomalies without a baseline. Many administrators run both.
Why does rkhunter warn after every system update?
rkhunter compares system binaries against stored hashes, so legitimate package updates look like changes. After updating from trusted sources, run rkhunter —propupd to record the new baseline. Many distributions can do this automatically after package installs.
Is Lynis a malware scanner?
No. Lynis is a security auditing tool. It checks your configuration against hardening best practices, such as SSH settings, file permissions, firewall status, and kernel parameters, and gives a hardening score with specific suggestions. It complements scanners rather than replacing them.
Can a rootkit hide from these tools?
Yes. A kernel-level rootkit controls what the running system reports, so scanners running on a compromised system can be fooled. For a trustworthy check, boot from clean live media and scan the disk offline, and treat a confirmed root compromise as requiring a rebuild.