I want to talk more about this on one of the morning shows. Lets talk about ftrace and how we can intercept code execution in the kernel. This could be a fabulous vector for another rootkit strategy.
https://www.kernel.org/doc/html/latest/livepatch/livepatch.html