Tracee

Linux runtime security and forensics using eBPF.

Visit Website →

Overview

Tracee is an open-source runtime security and forensics tool for Linux that is built on top of eBPF. It provides deep visibility into system behavior and can be used to detect and investigate security incidents.

✨ Key Features

  • Runtime security
  • Forensics
  • eBPF-based
  • Low overhead
  • Extensible

🎯 Key Differentiators

  • eBPF-based
  • Low overhead
  • Focus on forensics

Unique Value: Provides a powerful and flexible tool for runtime security and forensics that is built on top of modern kernel technologies.

🎯 Use Cases (3)

Detecting and investigating security incidents Monitoring system behavior Compliance

✅ Best For

  • Tracking file access
  • Monitoring network connections
  • Identifying suspicious process execution

💡 Check With Vendor

Verify these considerations match your specific requirements:

  • Static code analysis
  • Pre-runtime vulnerability scanning

🏆 Alternatives

Falco Sysdig Inspect Tetragon

Offers a more lightweight and efficient approach to runtime security than many other tools, thanks to its use of eBPF.

💻 Platforms

Linux

✅ Offline Mode Available

🔌 Integrations

Kubernetes Docker Prometheus Grafana

💰 Pricing

Contact for pricing
Free Tier Available

Free tier: Open source, no limits.

Visit Tracee Website →