detectors
NAME¶
tracee --detectors - Configure YAML detector search directories
SYNOPSIS¶
tracee --detectors [path...] [--detectors path...]
DESCRIPTION¶
The --detectors flag lets you add directories or files to search for YAML detectors and shared lists.
Each path can be a directory or a YAML file. If not specified, Tracee uses the default search path /etc/tracee/detectors.
EXAMPLES¶
-
Use the default search path:
tracee -
Add a custom directory:
--detectors /custom/detectors -
Add multiple directories:
--detectors /dir1 --detectors /dir2 -
Add a specific YAML detector file:
--detectors ./detectors/suspicious_exec.yaml -
Config file format:
detectors: - /custom/path1 - /custom/path2