Linux kernel architecture TL;DR: Syscalls, modules, eBPF surface — overview for kernel researchers. Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References TODO