aquasecurity/tracee

Linux Runtime Security and Forensics using eBPF

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 51 minutes ago
Added to GitGenius on May 25th, 2022
Created on September 18th, 2019
Open Issues & Pull Requests: 121 (+0)
Number of forks: 507
Total Stargazers: 4,590 (+0)
Total Subscribers: 57 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 3.2 days
Mean response time: 288.8 days
90th percentile: 1131.9 days
Tracked items: 352

How this project is maintained

Around half of the issues opened in the past year never receive a reply. 68% of open issues come from outside the core team, a mix of external reports and the maintainers' own roadmap. Work labelled "kind/bug" is answered fastest, typically in about 11 hours, while "area/ebpf" waits about 31 months. Only 4% of issues opened in the past year have been closed. Three people close 90% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 88
New in 7 days: 1
Closed in 7 days: 0
Avg open age: 877 days
Stale 30+ days: 87
Stale 90+ days: 82

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • kind/bug (344)
  • kind/feature (215)
  • area/ebpf (144)
  • priority/backlog (83)
  • kind/chore (53)
  • kind/documentation (42)
  • area/testing (32)
  • area/events (30)

Most active issues this week

Detailed Description

Tracee is a runtime security and observability tool developed by Aqua Security that leverages eBPF technology to monitor system and application behavior on Linux. The tool exposes system activity as consumable events, ranging from factual system calls to sophisticated security events that detect suspicious behavioral patterns. Written primarily in Go, Tracee enables users to understand what is happening on their systems in real time through deep kernel-level instrumentation.

The project is classified across multiple security and monitoring domains including compliance enforcement, anomaly detection, container security, runtime enforcement, system auditing, threat detection, and network monitoring. This breadth of classification reflects Tracee's versatility in addressing various security use cases from process tracking and system call tracing to network activity monitoring and policy compliance. The tool supports deployment across different environments, with specific installation guides and quickstart documentation available for Docker and Kubernetes deployments, as well as compatibility information for various Linux distributions and kernels.

Tracee's development has been actively maintained with significant community engagement. This distribution suggests the project maintains an active bug-fixing cadence while also managing feature requests and backlog items systematically.

These three individuals have driven the majority of development and maintenance work.

The tool's functionality centers on eBPF-based system instrumentation, allowing it to tap into kernel-level events without requiring kernel modifications or significant performance overhead. Users can consume events through various interfaces and integrate Tracee into their security workflows. The project provides comprehensive documentation covering installation prerequisites, Docker deployment, Kubernetes integration, and advanced configuration options including platform-specific guidance for macOS users.

Tracee positions itself as part of Aqua Security's broader open source portfolio and actively encourages community participation through GitHub Discussions, Slack channels, and formal contribution documentation. The project accepts user feedback and issue reports, maintaining an open development model that welcomes external contributions and community involvement in shaping the tool's evolution.