The fact that it is running in the kernel and isn’t a hardware driver or an OS level piece of software is probably triggering AV software. This is bad. Anything that runs in the kernel doesn’t just have to be trusted, but also secure.... which never reaches 100% as there are always bugs and/or vulnerabilities.... not…