All integrations

Tracee Integration with DefectDojo

Tracee Integration with DefectDojo

Tracee is an open source runtime security and forensics tool for Linux from Aqua Security. It uses eBPF to instrument system calls and Linux Security Module hooks in the kernel, records what processes and containers actually do, and evaluates that activity against behavioral signatures that flag suspicious patterns, many of them mapped to MITRE ATT&CK techniques. It can run on a host or in a Kubernetes cluster, and its JSON output writes one event per line, which DefectDojo imports.

Tracee Integration with DefectDojo

We run Tracee on our container hosts to see what workloads do at runtime, and DefectDojo is where its detections become something the team triages instead of something that scrolls by in a log stream. Importing Tracee's JSON turns each signature detection into a Finding with the severity Tracee assigned, tagged with its MITRE technique ID and tied to the container that triggered it. Raw traced events we asked for in our policies come in as Info, so they are recorded and searchable without competing with real detections. Because deduplication keys on the signature and the container rather than the timestamp, a behavior that repeats all day becomes one Finding with its repeats recorded as duplicates.

Why Tracee Matters

Static scanners and image scanners describe what could go wrong. Runtime monitoring shows what is happening, which is where an intrusion or a misbehaving workload first becomes visible.

  • eBPF instrumentation lets Tracee observe syscalls and security hooks across the host without modifying the workloads it watches.
  • Its signatures (for example, anti-debugging detection) are verdicts about activity, each with a severity and, where defined, a MITRE technique.
  • Each event carries the process, executable, container, image, and Kubernetes pod and namespace, which makes attribution to a workload direct.
  • Operators can define policies to trace specific events, which is useful for forensics and for confirming how an application behaves.

Advantages of This Integration

  • Detections and telemetry kept apart. Signature detections are titled ID: name with Tracee's severity; traced events are titled Traced event: name and import as Info, so the two are never confused in a queue.
  • Repeats folded into one Finding. DefectDojo hashes Tracee findings on the signature or event name and the Component Name (the container name, or host name outside a container), so recurring behavior does not flood the Asset.
  • MITRE context as tags. A detection's MITRE ID and Tracee's own metadata tags are added as Finding tags, so you can filter by technique across every Asset.
  • Workload attribution. Component Name holds the container (or host) and Component Version the image, so findings point at the workload to investigate or rebuild.
  • Standard triage. Detections can be assigned, annotated with investigation notes, risk accepted, marked false positive, or pushed to Jira, with SLAs by severity.
  • Correlation with build-time findings. Runtime detections sit on the same Asset as image CVEs and code findings for that service.

How This Integration Works

DefectDojo imports Tracee output with the Tracee Scan scan type.

1. Capture events as JSON. Run Tracee with JSON output and write the stream to a file:

tracee --output json > tracee.json

Tracee writes one JSON object per line; a JSON array is also accepted. Tracee's own structured log lines (objects with a level and no eventName) are skipped rather than imported. In practice, teams collect events for a fixed window or rotate the file, then import each batch.

2. Import it. In the UI, open the Engagement, choose Import Scan Results, select Tracee Scan, and upload the file. For automation, use the API in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Tracee Scan" 
  -F "file=@tracee.json" 
  -F "product_name=checkout-cluster" 
  -F "engagement_name=Runtime" 
  -F "auto_create_context=true"

DefectDojo Pro users can use Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Tracee Scan" 
  --report-path "./tracee.json" 
  --product-name "checkout-cluster" 
  --engagement-name "Runtime" 
  --auto-create-context

3. Decide on import or reimport. Runtime events are not a snapshot of state, so a behavior missing from the latest batch has not necessarily stopped. Importing each batch as a new Test and letting deduplication fold repeats avoids mitigating detections just because they were absent from one window.

Data Granularity: What Gets Imported

DefectDojo Field Source in Tracee Event Notes
Title Signature ID and name, or eventName TRC-102: Anti-Debugging detected or Traced event: setuid
Severity Signature Severity (0 to 4) 0 Info, 1 Low, 2 Medium, 3 High, 4 Critical; unknown is Medium; traced events are Info
Description Event and signature details Process, PIDs, user, return value, host, executable, container, image, pod, namespace, policies, arguments
Signature context Signature metadata Category, MITRE technique, and MITRE ID added to the description
Component Name container.name Falls back to hostName
Component Version container.image For example alpine:latest
Vulnerability ID from tool Signature ID or event name Used for filtering and deduplication
Tags MITRE ID and metadata tags Detections only
Finding type Dynamic All findings are dynamic
Deduplication Hashcode Vulnerability ID from tool, Component Name

Use Cases

Triage for container hosts: A security team imports Tracee detections from each cluster into its Asset every hour. New High and Critical detections are assigned to the on-call engineer, and duplicates show how often the behavior recurred.

Investigating a suspicious workload: When a detection fires for one container, filter that Asset by Component Name to see every detection and traced event for that workload, with process, executable, and arguments in each description.

Technique-level reporting: Because MITRE IDs are tags, security leads can report which ATT&CK techniques were detected across the estate in a given month and which services triggered them.

Validating a hardening change: After restricting a workload's capabilities, a team traces specific syscalls with a Tracee policy and imports the results. Info findings for those traced events show whether the workload still makes the calls.

Operational Tips

  • Keep traced-event policies narrow. Every traced event imports as an Info Finding, so tracing broad syscalls can produce large imports.
  • Use minimum_severity=Low on import if you only want signature detections and none of the Info traced events.
  • Name containers meaningfully. Component Name is part of the hashcode, so randomly generated container names stop repeats from folding together across restarts.
  • Arguments and executable paths are copied into the description. Review what your tracing policies capture before importing them into a shared instance.
  • To give a particular traced event more weight, filter on its event name in Vulnerability ID from tool and adjust severity in DefectDojo, rather than expecting Tracee to grade it.
  • Treat each Finding as a lead for investigation. A detection is Tracee's verdict about observed behavior, and confirming impact still needs a human.