
tracee
Linux Runtime Security and Forensics using eBPF

Linux Runtime Security and Forensics using eBPF

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use…

Real-time, container-based file scanning at enterprise scale

eBPF-based Linux security monitor and threat hunter providing chronologically ordered, container-aware events with on-host correlation for incident…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

the ps utility, with an eBPF twist and container context

Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes…

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

eBPF-powered silent observer for containerized runtimes, built for malware analysis sandboxes and Agentic AI monitoring.

A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine…

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

Your everyday Linux distribution gone Super Saiyan.

Linux Persistence Detection, Hunting and Artifact Collection script

A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…