Home Software Docker Explorer – a Tool to Help Forensicate Offline Docker Acquisitions

Docker Explorer – a Tool to Help Forensicate Offline Docker Acquisitions

0
0
2,008

This project helps a forensics analyst explore offline Docker filesystems.¬†Docker uses layered backend filesystems like¬†AuFS¬†or OverlayFS. Each layer is actually stored on the host’s filesystem as multiple folders, and some JSON files are used by Docker to know what is what.

  • Spotting the Signs of Lateral Movement

    Derek King has published another post as part of his¬†“Hunting with Splunk: The Basic…
  • How to Deploy Cuckoo Sandbox

    Marc Rivero L√≥pez presented a how-to guide that will help you to deploy¬†Cuckoo Sandbox …
  • DFIR SQL Query Repository

    Alexis Brignoni has started a collection of¬†SQL query templates for digital forensics use,…
Load More Related Articles
Load More In Software

Leave a Reply

Your email address will not be published. Required fields are marked *