logo

Go deeper: Linux runtime visibility meets Wireshark

ID: 69348bab-3d40-578f-9704-c1fe835d6c62

STIX ID: report--69348bab-3d40-578f-9704-c1fe835d6c62

Feed Name: Aqua Security Blog

Threat Score
55/100

Date Published: 2024-08-07

Date Updated: 2026-04-26

...
...

Traceeshark is a Wireshark plugin that brings Tracee's eBPF-based Linux runtime security events into Wireshark for interactive analysis, live capture, and correlation of host events with network traffic. The blog details installation, features (readers, dissectors, live capture), and demonstrates using Traceeshark to analyze the HeadCrab Redis-targeting malware—highlighting detections such as fileless memfd execution, dropped files, redirected I/O (remote shell), and process/network correlation—while emphasizing improved analyst workflows and artifact retrieval.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.