ELF bricking of reboot/shutdown/halt/poweroff binaries via ELFOOD overwrite

This rule detects attempts to sabotage or brick Linux systems by monitoring for modifications or overwrites of critical system binaries responsible for reboot, shutdown, and power management, including 'reboot', 'shutdown', 'halt', 'poweroff', 'systemctl', and 'telinit'. It specifically identifies activity associated with the 'ELFOOD' header-corruption marker, a technique linked to the Tengu malware strain which prevents legitimate system reboots to maintain persistence and impede remediation efforts.