Contents

Linux Tracee

Tracee

Tracee
Runtime Security and Forensics using eBPF.

Command Options

Binding

MountModeDescription
/lib/modules/Read OnlyKernel Headers
/usr/srcRead OnlyKernel Headers
/tmp/traceeDefaultDefault workspace

Additional Capability

Capabiltity
--privileged

Command Examples

Standard Output(Default)

1
docker run --name tracee --rm --privileged -v /lib/modules/:/lib/modules/:ro -v /usr/src:/usr/src:ro -v /tmp/tracee:/tmp/tracee -it aquasec/tracee:latest