Any tool on the suspect box has to be treated with caution, IME.

It's always handy to keep a few staticly-compiled binaries of things 
like ps and find and chkrootkit and sash - say - on a CD-R; if you 
suspect a compromise, put them on the suspect box and see if they 
give you anything more than the usual results.

(I find the various arguments of 'find' to be useful 'find -atime' or 
'find -mtime' - any half-clued kiddie will modify the timestamps, but 
there's often something that doesn't get changed and can give you 

- it should go without saying that the binaries need to be compiled 
for a system appropriate to your suspect box!

Additionally, lsof (http://www-rcd.cc.purdue.edu/~abe/) is invaluable 
for this sort of thing.

  best wishes,

    Gideon Hallett.

