Maybe there could be a SELinux icon in the system tray. It would show security notifications, like when a new crontab entry is created or a reverse shell is detected. Malware could silently add a crontab entry, and the user might not notice. The user could click the icon to view a log of past security alerts. There could be allow/block buttons. Only a superuser would be allowed to clear the log.
https://thehackernews.com/2025/06/chaos-rat-malware-targets-windows-and.html
https://securelist.com/backdoored-free-download-manager-linux-malware/110465/