logo

Tracee Newly Released Rules Detect Attackers Out-of-the-Box

ID: a9feeaed-ea62-5654-8f68-3ee40c84a0f6

STIX ID: report--a9feeaed-ea62-5654-8f68-3ee40c84a0f6

Feed Name: Aqua Security Blog

Date Published: 2022-11-10

Date Updated: 2026-04-26

...
...

Aqua Nautilus announces new and updated Tracee runtime detection signatures for Linux and container environments that map to MITRE ATT&CK techniques. The release highlights signatures for initial access (e.g., web server spawning a shell), privilege escalation and container escape (cgroups, docker.sock, kcore, kernel modules), persistence (cron, LD_PRELOAD, rcd), and defense evasion (proc/syscall hooking, fileless execution, anti‑debugging), intended to provide out‑of‑the‑box runtime detection of attacker behaviors based on Aqua's threat research.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.