Capture Linux runtime security events and suspicious behavior for live triage with Tracee

Watch live Linux and container activity through eBPF so you can triage suspicious runtime behavior before it disappears into guesswork.

agentskillexchange Updated 28 repo stars

File contents

Capture Linux runtime security events and suspicious behavior for live triage with Tracee

Watch live Linux and container activity through eBPF so you can triage suspicious runtime behavior before it disappears into guesswork.

Prerequisites

Linux host or Kubernetes environment with the required kernel support, Tracee runtime or container image, elevated access to collect eBPF events, and access to the target system or cluster

Installation

No source-backed install or usage instructions could be extracted automatically. Review the upstream project before running this skill in a sensitive workflow.

Documentation

Source

agentskillexchange/skills/tree/main/skills/capture-linux-runtime-security-events-and-suspicious-behavior-for-live-triage-with-tracee commit 1e3a48190f

Frequently asked questions

npx skillmds@latest add agentskillexchange/capture-linux-runtime-security-events-and-suspicious-behavio