ShadowGuard eBPF Rootkit - bpf() Syscall Non-Root or bpftool Interactive Shell (TGR-STA-1030)

Detects the use of BPF syscalls by non-root processes or the execution of BPF-related utilities (bpftool, bpfcc) from an interactive shell. This behavior is often associated with the ShadowGuard rootkit and potential BPF-based backdoor activity, which leverages BPF programs for stealthy system monitoring or command execution.