Tracee

Linux runtime security and forensics using eBPF.

Visit Website →

Overview

Tracee is an open-source runtime security and forensics tool for Linux. It is built by Aqua Security and uses eBPF to trace system calls and other kernel-level events. Tracee can be used to detect suspicious behavior, collect forensic data, and enforce security policies.

✨ Key Features

  • Runtime Security
  • Forensics
  • eBPF-based Tracing
  • Behavioral Monitoring
  • Policy Enforcement

🎯 Key Differentiators

  • eBPF-based architecture
  • Focus on both runtime security and forensics
  • Developed and maintained by Aqua Security

Unique Value: Provides a powerful and flexible tool for runtime security and forensics that is built on top of modern kernel technologies.

🎯 Use Cases (3)

Detecting and investigating security incidents Monitoring system behavior Compliance

✅ Best For

  • Tracking file access
  • Monitoring network connections
  • Identifying suspicious process execution

💡 Check With Vendor

Verify these considerations match your specific requirements:

  • Static code analysis
  • Pre-runtime vulnerability scanning

🏆 Alternatives

Falco Sysdig eBPF for Security

Offers a more lightweight and efficient approach to runtime security than many other tools, thanks to its use of eBPF.

💻 Platforms

Linux

✅ Offline Mode Available

🔌 Integrations

Kubernetes Docker Aqua Security

💰 Pricing

Contact for pricing
Free Tier Available

Free tier: Open source, no limits.

Visit Tracee Website →