logo

Uncover Malware Payload Executions Automatically with Tracee

ID: 25894940-0559-5dec-9243-0497ffb4763c

STIX ID: report--25894940-0559-5dec-9243-0497ffb4763c

Feed Name: Aqua Security Blog

Threat Score
10/100

Date Published: 2020-08-17

Date Updated: 2026-05-12

...
...

Tracee, an open-source container and system tracing tool, added two capabilities: capturing file writes (including files executed from memory such as memfd/fileless executions) and capturing dynamic code execution (detecting and extracting writable→executable memory regions). These features enable automatic extraction of in-memory or packed payloads for forensic analysis and scanning, improving the ability to uncover stealthy malware despite anti-analysis and obfuscation techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.