Tracee

A Linux runtime security and forensics tool that traces system events using eBPF.

These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.

About Tracee

Tracee uses eBPF to observe what happens on a Linux system at runtime, tracing system events for security monitoring and forensic investigation. The repository includes detectors and signatures for flagging suspicious behaviour, along with deployment files for running it on hosts and in container environments.

It is aimed at administrators and security teams who want visibility into processes and system calls on Linux machines. The project is actively developed on GitHub, with thousands of commits.

Strengths

  • eBPF-based tracing with low overhead on the kernel
  • Built-in detectors and signatures for suspicious activity
  • Useful for both live monitoring and forensics

Limitations

  • Linux only
  • Requires kernel eBPF support and administrator privileges
  • Aimed at security professionals rather than home users

Details

Pricing
FreeFree and open source.
License
Open source, license not stated
Developer
Aqua Security
Platforms
Linux, Command line
How it runs
Downloadable app
Account
Not required
Works offline
Yes
Best suited for
Security teams monitoring Linux hosts and containers at runtime
Last verified
Added
Provenance
Facts checked against the developer's own pages and store listings, 1 sources on file.

Alternatives to Tracee

Compare all

Software that can replace Tracee for an important use case, and what changes if you switch.

  • Falco

    Detect unusual runtime behavior on Linux systems.

    Falco detects unusual runtime behaviour on Linux by applying rules to system events and container context, under the Apache-2.0 license.

  • Tetragon

    An eBPF-based security observability and runtime enforcement tool for Linux hosts and Kubernetes clusters.

    Tetragon is also eBPF-based but adds real-time kernel-level enforcement and Kubernetes-aware events with pre-defined policy libraries, aimed mainly at Kubernetes environments.

Tracee as an alternative

Listings that name Tracee as an alternative.

  • Inspektor Gadget

    eBPF-based tools for inspecting and debugging Kubernetes clusters and Linux hosts.

    Tracee uses eBPF to trace Linux hosts and containers with built-in security detectors, aimed more at runtime security and forensics.

  • sysdig

    A Linux command-line tool for exploring and troubleshooting systems by capturing system calls, with container support.

    Tracee traces system events with eBPF and adds built-in security detectors, suiting runtime security and forensics more than general troubleshooting.

Similar software

Related functionality, not necessarily a direct replacement.

Report a wrong fact or a dead link on this listing