Watch live Linux and container activity through eBPF so you can triage suspicious runtime behavior before it disappears into guesswork.
Scanned 6/8/2026
Install via CLI
openskills install agentskillexchange/skills---
name: "Capture Linux runtime security events and suspicious behavior for live triage with Tracee"
slug: "capture-linux-runtime-security-events-and-suspicious-behavior-for-live-triage-with-tracee"
description: "Watch live Linux and container activity through eBPF so you can triage suspicious runtime behavior before it disappears into guesswork."
github_stars: 4468
verification: "listed"
source: "https://github.com/aquasecurity/tracee"
author: "Aqua Security"
publisher_type: "organization"
category: "Security & Verification"
framework: "Multi-Framework"
tool_ecosystem:
github_repo: "aquasecurity/tracee"
github_stars: 4468
---
# Capture Linux runtime security events and suspicious behavior for live triage with Tracee
Watch live Linux and container activity through eBPF so you can triage suspicious runtime behavior before it disappears into guesswork.
## Prerequisites
Linux host or Kubernetes environment with the required kernel support, Tracee runtime or container image, elevated access to collect eBPF events, and access to the target system or cluster
## Installation
No source-backed install or usage instructions could be extracted automatically. Review the upstream project before running this skill in a sensitive workflow.
- Source: https://github.com/aquasecurity/tracee
## Documentation
- https://aquasecurity.github.io/tracee/latest/
## Source
- [Agent Skill Exchange](https://agentskillexchange.com/skills/capture-linux-runtime-security-events-and-suspicious-behavior-for-live-triage-with-tracee/)
No comments yet. Be the first to comment!