Uncover Malware Payload Executions Automatically with Tracee
ID: 25894940-0559-5dec-9243-0497ffb4763c
STIX ID: report--25894940-0559-5dec-9243-0497ffb4763c
Feed Name: Aqua Security Blog
Tracee, an open-source container and system tracing tool, added two capabilities: capturing file writes (including files executed from memory such as memfd/fileless executions) and capturing dynamic code execution (detecting and extracting writable→executable memory regions). These features enable automatic extraction of in-memory or packed payloads for forensic analysis and scanning, improving the ability to uncover stealthy malware despite anti-analysis and obfuscation techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
