3 talks mention this tool across 3 BSides chapters.
Open-source eBPF-based tool for detecting kernel rootkit behaviors including module loading, hiding, hooking, and C2 communication