logo

The Story of Tracee: The Path to Runtime Security Tool

ID: cf1e44cc-9c08-5b7b-bc11-670db053c862

STIX ID: report--cf1e44cc-9c08-5b7b-bc11-670db053c862

Feed Name: Aqua Security Blog

Date Published: 2021-10-07

Date Updated: 2026-04-26

...
...

Tracee is an open-source eBPF-based runtime security and forensics tool for Linux from Aqua Security. The report explains Tracee's evolution from basic syscall tracing to a robust runtime detection platform with Tracee-eBPF (event collection) and Tracee-rules (behavioral detection), lists built-in detection signatures, and highlights v0.6.0 improvements including CO:RE portability, network capture, and new trace events.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.