Tracee
A Linux runtime security and forensics tool that traces system events using eBPF.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About Tracee
Tracee uses eBPF to observe what happens on a Linux system at runtime, tracing system events for security monitoring and forensic investigation. The repository includes detectors and signatures for flagging suspicious behaviour, along with deployment files for running it on hosts and in container environments.
It is aimed at administrators and security teams who want visibility into processes and system calls on Linux machines. The project is actively developed on GitHub, with thousands of commits.
Strengths
- eBPF-based tracing with low overhead on the kernel
- Built-in detectors and signatures for suspicious activity
- Useful for both live monitoring and forensics
Limitations
- Linux only
- Requires kernel eBPF support and administrator privileges
- Aimed at security professionals rather than home users
Details
- Pricing
- FreeFree and open source.
- License
- Open source, license not stated
- Developer
- Aqua Security
- Platforms
- Linux, Command line
- How it runs
- Downloadable app
- Account
- Not required
- Works offline
- Yes
- Best suited for
- Security teams monitoring Linux hosts and containers at runtime
- Categories
- System monitoring, Security tools
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Alternatives to Tracee
Compare allSoftware that can replace Tracee for an important use case, and what changes if you switch.
Falco
Detect unusual runtime behavior on Linux systems.
Falco detects unusual runtime behaviour on Linux by applying rules to system events and container context, under the Apache-2.0 license.
Tetragon
An eBPF-based security observability and runtime enforcement tool for Linux hosts and Kubernetes clusters.
Tetragon is also eBPF-based but adds real-time kernel-level enforcement and Kubernetes-aware events with pre-defined policy libraries, aimed mainly at Kubernetes environments.
Tracee as an alternative
Listings that name Tracee as an alternative.
Inspektor Gadget
eBPF-based tools for inspecting and debugging Kubernetes clusters and Linux hosts.
Tracee uses eBPF to trace Linux hosts and containers with built-in security detectors, aimed more at runtime security and forensics.
sysdig
A Linux command-line tool for exploring and troubleshooting systems by capturing system calls, with container support.
Tracee traces system events with eBPF and adds built-in security detectors, suiting runtime security and forensics more than general troubleshooting.
Similar software
Related functionality, not necessarily a direct replacement.
Sysmon
A Sysinternals service that logs detailed process, network and file activity to the Windows event log.
Kubescape
Assess Kubernetes configuration and runtime security.
Wazuh Agent
Endpoint agent that feeds a Wazuh server with security and compliance data.
gVisor
An application kernel that sandboxes containers to isolate them from the host Linux kernel.
Velociraptor
Endpoint monitoring and digital forensics platform driven by a query language.