Skip to content
Back to the index

runtime-trace

PyPIInfrastructure

PulseGate's liveness check found it on 4 Oct 2026; it is registered on GitHub and PyPI and has been in the index since 4 Oct 2026. How this is checked

runtime-trace is an open-source Linux command-line tool for cross-layer runtime consistency checking. It uses eBPF to identify hidden processes or modules and fileless execution patterns for digital forensics and blue-team investigations.

Inferred · not functionally tested

Open SourceMITCLISelf-hosted
Visit PyPI

Overview

6 features

Purpose: Detecting hidden processes, kernel modules, and fileless execution during Linux incident response.

Inferred · not functionally tested

Audience: DFIR practitioners and blue-team security analysts

Inferred · not functionally tested

Functions: monitoring, data_extraction

Inferred · not functionally tested

Interfaces: API: unknown · MCP: unknown · CLI: indicated (inferred, not tested) · Self-hosting: indicated (inferred, not tested)

Recorded constraints: pricing: open_source · license: MIT · platforms: CLI · deployment: cli, self_hosted

Constraint provenance is unknown; confirm requirements with the publisher.

Record sources: pypi.org · github.com. These links do not verify the individual claims.

runtime-trace sits in PulseGate's Malware analysis & digital forensics category. Inferred · not functionally tested: It focuses on detecting hidden processes, kernel modules, and fileless execution during Linux incident response. Inferred · not functionally tested: runtime-trace is an open-source project aimed at DFIR practitioners and blue-team security analysts. Basis unknown · not verified: runtime-trace is open source under the MIT license. Basis unknown · not verified: runtime-trace is available on the command line, and it can be self-hosted.

Jack Sessions builds and maintains runtime-trace, and it first shipped in 2026. Development happens publicly on GitHub with 3 commits in the last 90 days. Inferred · not functionally tested: Key capabilities include process hiding detection, module hiding detection, and fileless execution detection.

Summary written by a language model from the project’s public pages.

Tasks: Inferred · not functionally tested

  • Process hiding detection
  • Module hiding detection
  • Fileless execution detection
  • eBPF instrumentation
  • Cross-layer consistency checks
  • Linux runtime analysis

Topics: Inferred · not functionally tested

Tags
linux-forensicsebpf-monitoringrootkit-detectionincident-response

JSON profile · Text profile · Access guide

Built with & integrations

Runs on
CLISelf-hosted

Trust & compliance

License
MIT
Public signals
HTTPSOpen SourceFree tierGitHubActive maintenance

Indexing history

1

What PulseGate has recorded for this listing

  1. Indexed4 Oct · 00:56 UTC
    runtime-trace seen via PyPI Bulk Enumerator
    Source: PyPI Bulk Enumerator · Open

Frequently asked questions about runtime-trace

What is runtime-trace?
Inferred · not functionally tested: Runtime-trace focuses on detecting hidden processes, kernel modules, and fileless execution during Linux incident response. It is catalogued under Malware analysis & digital forensics on PulseGate.
Who is runtime-trace for?
Inferred · not functionally tested: runtime-trace is an open-source project built for DFIR practitioners and blue-team security analysts.
Does runtime-trace have a free plan?
Basis unknown · not verified: Yes — runtime-trace is open source under the MIT license and free to use.
What platforms does runtime-trace run on?
Basis unknown · not verified: runtime-trace runs on the command line. It can also be self-hosted.
Is runtime-trace still maintained?
PulseGate's liveness check found it on 4 Oct 2026. Its GitHub repository shows 3 commits in the last 90 days.
What projects are similar to runtime-trace?
Similar projects tracked by PulseGate include Hindsight Foundry, torikago, and phantom-trace-ntfs.Hindsight Foundrytorikagophantom-trace-ntfs
Who makes runtime-trace?
runtime-trace is developed by Jack Sessions.
How long has runtime-trace been around?
runtime-trace first shipped in 2026.

Also in Malware analysis & digital forensics

Same category — not a similarity match