Detecting Malicious Activity in CI/CD Pipeline with Tracee
ID: 27fe5bd3-7a54-56f6-8a5e-72380e98f9ea
STIX ID: report--27fe5bd3-7a54-56f6-8a5e-72380e98f9ea
Feed Name: Aqua Security Blog
This post demonstrates how to embed Tracee into GitHub Actions CI pipelines to detect and respond to malicious runtime behavior. It provides a step-by-step demo—creating a simple app, running Tracee as a service container in the workflow, triggering a proof-of-concept malicious action that opens a socket to stdin, and configuring the pipeline to fail when Tracee flags suspicious events—showing how Tracee can help ‘shift left’ security for CI/CD.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
