Cross-view LKM rootkit detector — proves Elastic Security EDR misses a hidden kernel module, detects it via /proc vs /sys diff
-
Updated
May 19, 2026 - Shell
Cross-view LKM rootkit detector — proves Elastic Security EDR misses a hidden kernel module, detects it via /proc vs /sys diff
Add a description, image, and links to the lkm-rootkit topic page so that developers can more easily learn about it.
To associate your repository with the lkm-rootkit topic, visit your repo's landing page and select "manage topics."