{"repo":"aquasecurity/traceeshark","free":true,"listed":false,"github":"https://github.com/aquasecurity/traceeshark","clone":"git clone https://github.com/aquasecurity/traceeshark.git","description":"Deep Linux runtime visibility meets Wireshark","language":"C","stars":311,"topics":["epbf","linux","malware-analysis","runtime-security","security","tracee","tracing","wireshark"],"license":"GPL-2.0","category":"security-tools","readme_excerpt":"1. What is Traceeshark? 2. Getting started 3. Basic usage 4. Build from source What is Traceeshark? Traceeshark brings the world of Linux runtime security monitoring and advanced system tracing to the familiar and ubiquitous network analysis tool Wireshark. Using Traceeshark, you can load Tracee captures in JSON format into Wireshark, and analyze them using Wireshark's advanced display and filtering capabilities. Traceeshark also provides the ability to analyze system events side by side with network packets generated by Tracee that contain rich context about the system process and container they belong to. Another feature of Traceeshark is the ability to capture events using Tracee directly from Wireshark and have them stream in like a network capture. This can be done either locally on a Linux machine running Wireshark, semi-locally using docker desktop’s VM on Windows and Mac, or even remotely over SSH. For an overview of Traceeshark and an example of how it can be used for malware analysis, you can read Go deeper: Linux runtime visibility meets Wireshark. Getting started The simplest way to install Traceeshark is using the autoinstall script. First, make sure you have Python 3 installed, and your Wireshark installation is updated to the latest version. Then, simply run the following command: Windows (powershell) Linux/Mac :information source: Note that Traceeshark is compiled for a specific Wireshark verison. If you are using a Linux distribution with an outdated Wireshar","default_branch":null,"files":null,"tree":[],"storefront":"/r/aquasecurity","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/aquasecurity/traceeshark/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}