Docker Forensics Toolkit Logo

Docker Forensics Toolkit

0
Free
Visit Website

This toolkit allows for post-mortem analysis of Docker runtime environments using forensic HDD copies of the docker host system. Features include mounting forensic images, displaying status information, listing images and containers, showing image history and configuration, displaying container logs, mounting container file systems, and extracting file system metadata for creating timelines.

FEATURES

ALTERNATIVES

Toolkit for performing acquisitions on iOS devices with logical and filesystem acquisition support.

A command-line tool for creating hex dumps, converting between binary and human-readable representations, and patching binary files.

dc3dd is a patch to the GNU dd program, tailored for forensic acquisition with features like hashing and file verification.

Free software for extracting Microsoft cabinet files, supporting all features and formats of Microsoft cabinet files and Windows CE installation files.

A library to access and parse Windows NT Registry File (REGF) format.

Powerful tool for searching and hunting through Windows forensic artefacts with support for Sigma detection rules and custom Chainsaw detection rules.

TestDisk is a free data recovery software that can recover lost partitions and undelete files from various file systems.

Customizable live OS constructor tool for remote forensics and incident response.