Hello and welcome to LQ, hope you like it here.
There's nothing that we can call a true equivalent of Dtrace AFAIK, but the Linux Trace Toolkit (LTT, 2.6 kernels) or SysCallTrack (SCT, 2.4 series) could help. For example in SCT you would just define a rule like:
Code:
rule
{
syscall_name = create_module
rule_name = root_create_module_rule
filter_expression {UID==0}
action { type = LOG }
}