Datadog interview question

-How would you detect a rootkit -How would you design a security rule