yes please post your thoughts re Kinoite, I've been running everyday for about a month and have had no issues (that I'm aware of). I don't update the ostree everyday.
No, they will absolutely not stop a zero-day rootkit.Use a layered approach instead of old-school signature scanner.Lynis Security Auditing,AIDE / Tripwire,Fail2Ban + SSH Keys.