A Mac OS X Rootkit Uses the Tricks You Haven’t Known Yet 2 - Detecting a Process Hidden by RubilynTaiwanese researcher Sung-ting Tsai, aka TT, now delves deeper into the ins and outs of process
hiding on Mac OS X, in particular through the use of the Rubilyn rootkit. The flip
side of the coin, that is, detecting a process that had been hidden, is
analyzed as well to show how user mode can be helpful in this context. For the
purpose of visualization, there are demos demonstrating these tricks in action.
Source:
A Mac OS X Rootkit Uses the Tricks You Haven’t Known Yet 2 - Detecting a Process Hidden by Rubilyn