It’s real, IBM used it when I worked there (early 2020s). Still better than crowdstrike, which required specific kernel versions and slows workstations to a halt. I still remember when GDC got spit out into Kyndryl (absolute meme of a company) and within months of announcing partnership with Microslop banned usage of Linux on workstations. Then they gave me a top-spec 2019 16in MBP that used 100% od the CPU and lagged… during the Teams call with the client. It was the reason why I’ve quit that job.
Deploy Microsoft Defender for Endpoint on Linux manually - Microsoft Defender for Endpoint
Describes how to deploy Microsoft Defender for Endpoint on Linux manually from the command line.