logo

Detecting Malicious Activity in CI/CD Pipeline with Tracee

ID: 27fe5bd3-7a54-56f6-8a5e-72380e98f9ea

STIX ID: report--27fe5bd3-7a54-56f6-8a5e-72380e98f9ea

Feed Name: Aqua Security Blog

Date Published: 2021-05-12

Date Updated: 2026-04-26

...
...

This post demonstrates how to embed Tracee into GitHub Actions CI pipelines to detect and respond to malicious runtime behavior. It provides a step-by-step demo—creating a simple app, running Tracee as a service container in the workflow, triggering a proof-of-concept malicious action that opens a socket to stdin, and configuring the pipeline to fail when Tracee flags suspicious events—showing how Tracee can help ‘shift left’ security for CI/CD.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.