Skip to content

Malah/tracee

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Tracee Logo

GitHub release (latest by date) License docker

Tracee: Runtime Security and Forensics using eBPF

Tracee uses eBPF technology to tap into your system and give you access to hundreds of events that help you understand how your system behaves. In addition to basic observability events about system activity, Tracee adds a collection of sophisticated security events that expose more advanced behavioral patterns. Tracee provides a rich filtering mechanism that allows you to eliminate noise and focus on specific workloads that matter most to you.

Key Features:

  • Kubernetes native installation
  • Hundreds of default events
  • Ships with a basic set of behavioral signatures for malware detection out of the box
  • Easy configuration through Tracee Policies
  • Kubernetes native user experience that is targetted at cluster administrators

We release new features and changes on a regular basis. Learn more about the latest release in our discussions.

To learn more about Tracee, check out the documentation.

Quickstart

Installation options:

Steps to get started:

  1. Install Tracee in your Kubernetes cluster through Helm
  2. Query logs to see detected events

Next, try one of our tutorials:

  1. Filter events through Tracee Policies
  2. Manage logs through Grafana Loki or your preferred monitoring solution

Example log output in Tracee pod Example log output in Tracee pod

Contributing

Join the community, and talk to us about any matter in the GitHub Discussions or Slack.
If you run into any trouble using Tracee or you would like to give us your feedback, please create an issue.

Find more information on contributing to the source code in the documentation.

Please consider giving us a star ⭐️ by clicking the button at the top of the GitHub page

More about Aqua Security

Tracee is an Aqua Security open source project.
Learn about our open source work and portfolio here.

About

Linux Runtime Security and Forensics using eBPF

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Go 81.8%
  • C 15.0%
  • Open Policy Agent 1.1%
  • Shell 1.1%
  • Other 1.0%