aquasecurity/tracee
Linux Runtime Security and Forensics using eBPF observed · 2026-08-28
Health v2 · maintenance only
79/100
- Activity 97
- Release rhythm 45
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 33.0
- age_days: 2541
- days_rel: 288
- days_push: 22
- n_releases_24m: 11
Adoption not part of the score
4593 stars · 507 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Tracee is a Linux runtime security and forensics tool that uses eBPF to trace system calls, network activity, and file operations in real time. It exposes system activity as events and detects suspicious behavioral patterns for threat detection and observability.
Use cases
- detect malware and privilege escalation on linux hosts
- monitor container and kubernetes runtime security
- trace syscalls and process execution for forensics
- debug application behavior and system issues
- monitor file access and data exfiltration for compliance
- get real-time security alerts from eBPF events
When to choose
- you need eBPF-based runtime threat detection on Linux
- you run containers or Kubernetes and need container-aware security monitoring
- you want deep system observability without modifying application code
When to avoid
- you need security monitoring on macOS or Windows
- your kernel or distribution lacks eBPF support
- you only need static vulnerability scanning rather than runtime analysis
Facets
cli-tool · maturity active
security monitoring tracing alerting security monitoring operating-systems go ebpf runtime-security forensics bpf container-security threat-detection syscalls containers devops linux docker kubernetes
2 sources
- readme: https://github.com/aquasecurity/tracee · fetched 2026-08-28 · b3001e4ec1be
- homepage: https://aquasecurity.github.io/tracee/latest · fetched 2026-08-29 · 03b1e2cdf4ab
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| aquasecurity/tracee | main | 79 |
For agents
markdown · JSON · MCP: product_card(name="aquasecurity/tracee")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem