Docker Forensics Toolkit

Docker Forensics Toolkit

#Incident Management#Digital Forensics

A repository containing material from a talk on sub-domain enumeration techniques

Visit Website

This toolkit enables post-mortem analysis of Docker environments

This toolkit enables the post-mortem analysis of Docker runtime environments by utilizing forensic HDD copies from the Docker host system.

Features include mounting forensic images and more

Features include the ability to mount forensic images, display status information, list images and containers, show image history and configuration, display container logs, mount container file systems, and extract file system metadata for the purpose of creating timelines.