# Capture Linux runtime security events and suspicious behavior for live triage with Tracee

> Watch live Linux and container activity through eBPF so you can triage suspicious runtime behavior before it disappears into guesswork.

- Skill: `agentskillexchange/capture-linux-runtime-security-events-and-suspicious-behavio` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/capture-linux-runtime-security-events-and-suspicious-behavio`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/capture-linux-runtime-security-events-and-suspicious-behavio/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/capture-linux-runtime-security-events-and-suspicious-behavio

---


# Capture Linux runtime security events and suspicious behavior for live triage with Tracee

Watch live Linux and container activity through eBPF so you can triage suspicious runtime behavior before it disappears into guesswork.

## Prerequisites

Linux host or Kubernetes environment with the required kernel support, Tracee runtime or container image, elevated access to collect eBPF events, and access to the target system or cluster

## Installation

No source-backed install or usage instructions could be extracted automatically. Review the upstream project before running this skill in a sensitive workflow.

- Source: https://github.com/aquasecurity/tracee

## Documentation

- https://aquasecurity.github.io/tracee/latest/

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/capture-linux-runtime-security-events-and-suspicious-behavior-for-live-triage-with-tracee/)

