Go deeper: Linux runtime visibility meets Wireshark
ID: 69348bab-3d40-578f-9704-c1fe835d6c62
STIX ID: report--69348bab-3d40-578f-9704-c1fe835d6c62
Feed Name: Aqua Security Blog
Traceeshark is a Wireshark plugin that brings Tracee's eBPF-based Linux runtime security events into Wireshark for interactive analysis, live capture, and correlation of host events with network traffic. The blog details installation, features (readers, dissectors, live capture), and demonstrates using Traceeshark to analyze the HeadCrab Redis-targeting malware—highlighting detections such as fileless memfd execution, dropped files, redirected I/O (remote shell), and process/network correlation—while emphasizing improved analyst workflows and artifact retrieval.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
