awesome-repositories.com
Blog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetÀ proposNotre méthodologiePresseServeur MCP
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
aquasecurity avatar

aquasecurity/tracee

0
View on GitHub↗
4,377 stars·484 forks·Go·apache-2.0·7 vuesaquasecurity.github.io/tracee/latest↗

Tracee

Tracee is a cloud-native runtime security and forensics tool that uses eBPF to capture system calls and kernel events in real time. It operates as a standalone binary or a Helm-deployable agent for Kubernetes, normalizing system calls, network events, and container activities into a unified event pipeline for consistent analysis.

The tool distinguishes itself through policy-driven event filtering using YAML-based rules, allowing users to target specific workloads and reduce noise during monitoring. It includes built-in threat detection signatures that flag suspicious behavioral patterns without requiring custom rules, and it collects forensic artifacts such as memory dumps, binaries, and network traffic for post-incident investigation.

Tracee provides comprehensive system observability by tracking over 400 system events, including process execution, file operations, and network activity. It generates real-time security alerts and supports incident investigation through detailed audit trails with process lineage and file paths. The tool is designed for monitoring containerized environments and Kubernetes clusters without requiring application modifications.

Features

  • Monitors - Deploys as a container or Helm chart to audit system events and enforce policies in Kubernetes clusters.
  • Observability Tools - Deploys a monitoring agent via Helm chart to audit system activity and detect threats across Kubernetes clusters.
  • eBPF Runtime Security Monitors - Monitors containerized and host workloads in real time to detect security threats using eBPF-based system call analysis.
  • Containerized Environment Monitors - Monitors containerized environments and Kubernetes without requiring changes to existing applications.
  • Unified Event Normalizers - Normalizes system calls, network events, and container activities into a single event stream for consistent processing.
  • eBPF Security Tools - Monitors system calls and application behavior in real time using eBPF to detect threats in containerized environments.
  • Behavioral Threat Detection - Analyzes event streams to identify security threats and anomalous behavioral patterns in containerized environments.
  • Cloud Native - Applies behavioral patterns and pre-defined signatures to identify suspicious activity across distributed workloads.
  • Monitoring Policies - Defines flexible, configurable policies to control what system events to monitor and how to respond.
  • YAML Detection Policies - Creates scoped, filterable security policies using a few lines of YAML, deployable across environments.
  • Threat Detection - Analyzes system events in real time to identify suspicious behavior patterns and potential security threats.
  • Signature-Based Threat Detectors - Matches system event streams against pre-defined behavioral signatures to flag suspicious activity without custom rules.
  • Security Alert Triggers - Generates events for immediate threat detection and response when suspicious activity is observed.
  • YAML-Based Event Filters - Defines scoped, YAML-based policies to target specific workloads and reduce noise during kernel event capture.
  • Kernel Event Observability - Captures system calls and kernel events in real time by attaching eBPF programs to kernel hooks.
  • System Call Monitors - Tracks system calls, process execution, file operations, and network activity to provide deep visibility into Linux system behavior.
  • eBPF-Based Activity Monitors - Captures system calls and application behavior via eBPF to expose live events for security and observability.
  • System Event Monitors - Captures over 400 system calls, network events, and container activities as unified events for comprehensive security monitoring.
  • Forensic Artifact Collection - Captures network traffic, binaries, memory dumps, and file artifacts for post-incident investigation and compliance.
  • Helm Chart Deployment - Packages the monitoring agent as a Helm chart for declarative deployment in Kubernetes clusters.
  • Standalone Binaries - Runs as a self-contained binary that can be deployed directly on hosts without container runtime dependencies.
  • Audit Trail Investigators - Investigates security incidents using detailed audit trails with process lineage, file paths, and network connections.
  • Container Forensics Collection - Captures memory dumps, binaries, and network traffic from containers for post-incident investigation and compliance.
  • Built-in Threat Signatures - Ships pre-built threat detection signatures that flag suspicious behavior without requiring custom rules.
  • Forensics and Incident Response - Linux runtime security and forensics using eBPF.
  • Networking and Security - Runtime security and forensics tool for Linux.
  • Security Lab Environments - Runtime security and forensics tool using eBPF.

Historique des stars

Graphique de l'historique des stars pour aquasecurity/traceeGraphique de l'historique des stars pour aquasecurity/tracee

Recherche par IA

Explorez plus de dépôts awesome

Décrivez vos besoins en langage naturel — l'IA classe des milliers de projets open source sélectionnés par pertinence.

Start searching with AI

Alternatives open source à Tracee

Projets open source similaires, classés selon le nombre de fonctionnalités partagées avec Tracee.
  • cilium/tetragonAvatar de cilium

    cilium/tetragon

    4,753Voir sur GitHub↗

    Tetragon is an eBPF-based runtime security and observability toolset designed for Linux and Kubernetes environments. It functions as a security policy manager, observability agent, and enforcement engine that hooks into kernel functions and tracepoints to detect privilege escalation, container escapes, and unauthorized system activity. The project distinguishes itself through its ability to perform real-time, in-kernel enforcement, allowing it to synchronously terminate malicious processes or modify function return values before a system call completes. It provides deep Kubernetes integration

    C
    Voir sur GitHub↗4,753
  • velocidex/velociraptorAvatar de Velocidex

    Velocidex/velociraptor

    3,769Voir sur GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    Voir sur GitHub↗3,769
  • kubescape/kubescapeAvatar de kubescape

    kubescape/kubescape

    11,489Voir sur GitHub↗

    Kubescape is a Kubernetes security posture management platform designed to scan clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance risks. It functions as a comprehensive security suite incorporating a compliance scanner, a container image vulnerability scanner, an admission controller for policy enforcement, and a runtime security monitor. The platform distinguishes itself through runtime-aware vulnerability filtering, which maps libraries loaded in memory to determine if vulnerabilities are actually reachable. It also integrates with AI assistants via a Mo

    Gobest-practicedevopskubernetes
    Voir sur GitHub↗11,489
  • comodosecurity/openedrAvatar de ComodoSecurity

    ComodoSecurity/openedr

    2,603Voir sur GitHub↗

    OpenEDR is an endpoint detection and response platform designed to collect telemetry and monitor system activity to identify security breaches. It functions as a host-based intrusion detection system and telemetry collector, gathering detailed data on process, network, and file activity. The system includes a dockerized security stack that bundles search, logging, and visualization tools into containers for analyzing endpoint telemetry. It features a security event visualizer that maps process lineage and indexes logs to facilitate root-cause analysis of attacks. The platform provides capabi

    C++
    Voir sur GitHub↗2,603
Voir les 30 alternatives à Tracee→

Questions fréquentes

Que fait aquasecurity/tracee ?

Tracee is a cloud-native runtime security and forensics tool that uses eBPF to capture system calls and kernel events in real time. It operates as a standalone binary or a Helm-deployable agent for Kubernetes, normalizing system calls, network events, and container activities into a unified event pipeline for consistent analysis.

Quelles sont les fonctionnalités principales de aquasecurity/tracee ?

Les fonctionnalités principales de aquasecurity/tracee sont : Monitors, Observability Tools, eBPF Runtime Security Monitors, Containerized Environment Monitors, Unified Event Normalizers, eBPF Security Tools, Behavioral Threat Detection, Cloud Native.

Quelles sont les alternatives open-source à aquasecurity/tracee ?

Les alternatives open-source à aquasecurity/tracee incluent : cilium/tetragon — Tetragon is an eBPF-based runtime security and observability toolset designed for Linux and Kubernetes environments.… velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… kubescape/kubescape — Kubescape is a Kubernetes security posture management platform designed to scan clusters, manifests, and images for… comodosecurity/openedr — OpenEDR is an endpoint detection and response platform designed to collect telemetry and monitor system activity to… falcosecurity/falco — Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and… cilium/hubble — Hubble is an eBPF-based Kubernetes observability platform designed for network monitoring, security auditing, and flow…