This project helps a forensics analyst explore offline Docker filesystems. When analyzing a system where a Docker container has been compromised, it can be useful to have the same view of the filesystem as the container's. Docker uses layered backend filesystems like AuFS or OverlayFS, with each layer stored on the host's filesystem as multiple folders. Some JSON files are used by Docker to know what is what. Installation methods include PPA, PyPI, and cloning the repository. Usage involves finding the interesting container ID, mounting the container's filesystem in /mnt/container, and using tools like log2timeline.py or ls.
FEATURES
ALTERNATIVES
Python tool for remotely or locally dumping RAM of a Linux client for digital forensics analysis.
A comprehensive incident response tool for Windows computers, providing advanced memory forensics and access to locked systems.
A collection of PowerShell modules for artifact gathering and reconnaissance of Windows-based endpoints.
Tool for parsing Android logs events and protobuf data
A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys.
A library for working with Windows NT data types, providing access and manipulation functions.
A free, open-source file data recovery software that can recover lost files from hard disks, CD-ROMs, and digital camera memory.
PINNED
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.