https://cyberpress.org/linux-rootkit-abuses-elastic-trusted_pids-ebpf-map/
Linux rootkit targets Elastic trusted_pids path Research on the Singularity Linux rootkit shows a loader can abuse Elastic Defend’s trusted_pids eBPF map to suppress module_load telemetry during malicious kernel module insertion. Testing cited Elastic Defend 9.5.2 on Ubuntu 6.8.0-138, where the BPF program exits early if the loading process is marked trusted, preventing module metadata collection and event creation.