Tracee is a runtime security and observability tool that utilizes eBPF technology to tap into your system, exposing information as events ranging from system activity to sophisticated security events detecting suspicious behavioral patterns. For more information, refer to the documentation. To quickly try Tracee, use the provided Docker snippet on common Linux distributions and kernels.
FEATURES
SIMILAR TOOLS
InQL is a Burp Suite extension for advanced GraphQL testing and vulnerability detection
Tenable One Exposure Management Platform is a comprehensive platform for vulnerability management and exposure management.
App-Ray offers comprehensive security analysis and compliance solutions for mobile applications.
DerScanner is a comprehensive application security testing platform that combines SAST, DAST, MAST, SCA, and Binary Analysis capabilities with support for on-premises deployment and CI/CD integration.
A lightweight web security auditing toolkit that simplifies security tasks and enhances productivity.
Application monitoring and security platform that provides runtime visibility, threat detection, and automated response capabilities for application-layer security
IronBee is an open source project building a universal web application security sensor.
A web application firewall and API security platform that combines API discovery, runtime protection, vulnerability testing, and security posture management.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.