logo

Tracee: Tracing Containers with eBPF

ID: 50746be8-a9ea-5f74-9a4e-94d2814a11bd

STIX ID: report--50746be8-a9ea-5f74-9a4e-94d2814a11bd

Feed Name: Aqua Security Blog

Date Published: 2019-11-06

Date Updated: 2026-04-26

...
...

Aqua Security announces Tracee, an experimental open-source tool that uses eBPF to trace container-specific events. Tracee detects containers by watching for processes that appear as PID 1 inside new PID namespaces and then traces those processes and their children to capture syscalls and events (e.g., cap_capable); it focuses on container-only events and must be started before the containers to be traced. The project, authored by Yaniv Agman, supports common system calls and invites user feedback and contributions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.