Is there a way to detect fileless kernel compromise in Linux?
The only one way to analyze this kind of attack is by volatility. Volatility is a very good product, but not often updated especially with modern kernels (obviously because kernel change often), so it gives false positives.
Is there any alternative way to check the running kernel?