Copy Fail Vulnerability Mitigation Activity

Detects the execution of commands used to disable the algif_aead module to mitigate CVE-2026-31431 (Copy Fail). This rule monitors for dynamic unloading of the module using 'rmmod' or persistent configuration changes via 'modprobe.d' to disable the module. While this is a mitigation step, monitoring for it ensures compliance and tracks remediation efforts.