Tracee v0.23.0 Released! #4625
geyslan
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
We are excited to announce the release of Tracee v0.23.0! This release brings significant improvements, new features, and crucial fixes to enhance security monitoring and performance. Below are the key highlights:
🔥 New Features
stack_pivotEvent: Detects stack pivot techniques used in ROP exploits by checking the user’s stack pointer during key syscalls. (feat(events): add stack_pivot event #4403)suspicious_syscall_sourceEvent: Detects anomalies in syscall sources, improving security monitoring. (Addsuspicious_syscall_sourceevent #3953)chmod_commonEvent: (feat(events): add chmod_common event #4339)🛠️ Fixes & Improvements
Proctree
Other
hidden_kernel_moduleScan: Improved compatibility with kernels >6.2, preventing potential slice out-of-bounds errors. ( fix hidden_kernel_module history scan for kernels >6.2 #4378)/procParsing: Reduced execution time by 64% and memory usage by 27%, improving process info retrieval. (/proc parsing refactor #4364)📦 Dependency & Build Updates
For full details, see the release notes.
We appreciate your contributions and feedback - keep them coming! 🎉
Beta Was this translation helpful? Give feedback.
All reactions