I heard that a rootkit can hide itself and specified files, processes, and network links.
I know it can set a file to be hidden, but how does it hide a process?
Such as, there is a httpd
process running so that ps -ef
does not show the httpd
process.