Checking for kernel module rootkits

Section heading:

[Kernel]

Entries:

KernelCheckActive=true/false — 'true' to switch on, 'false' to switch off.

KernelCheckInterval=seconds — Interval between checks.

KernelCheckIDT=true/false — Check the Interrupt Descriptor Table (default true).

SeverityKernel=severity — Severity for events.