Hello *,
by digging into that topic, I bumped into https://capsule8.com/blog/dont-get-kicked-out-a-tale-of-rootkits-and-other-b... a while ago. In my humble opinion, this is a rare example of an useful comparison of different Linux rootkit types and techniques.
Regarding Linux kernel hardening, these resources might also be of interest: - https://capsule8.com/blog/millions-of-binaries-later:-a-look-into-linux-hard... - https://capsule8.com/blog/kernel-configuration-glossary/
I unfortunately did not have time yet to check whether IPFire can be improved here. Perhaps something to do over Christmas...
Thanks, and best regards, Peter Müller