Linux #rootkit taxonomy and hooking techniques (part. 1):
https://www.elastic.co/security-labs/linux-rootkits-1-hooked-on-linux

Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft — Elastic Security Labs
In this first part of a two-part series, we explore Linux rootkit taxonomy, trace their evolution from userland shared object hijacking and kernel-space loadable kernel module hooking to modern eBPF- and io_uring-powered techniques.



