You're calling unhide from rkhunter. Running unhide takes about 70s on my system.
I've made a Ruby port of unhide. It runs in about 7s on my system. So in one tenth of the time it performs the same checks as "unhide-linux26 proc" and "unhide-linux26 sys".
Would you be interested in calling unhide.rb rather than unhide from rkhunter?
Currently unhide.rb exits with code 2 if it finds something, and all output is printed to stdout, so it should be easy to interact with.
Code is here (one file only):
Bugs etc can be reported here:
Log in to post a comment.