IT Forensics · Linux

Forensic analysis of Docker images – tracing the origin and contents of container images

Docker images form the layered foundation for containers and contain both the actual application software and all associated dependencies in the form of individual, interdependent layers.

Enquire without obligation

Analysing an image can provide insight into which software and configuration were actually available in a container, regardless of whether the container itself still exists.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We analyse Docker images, including their individual layers, extract the software and configuration components they contain, and verify the origin of an image using available metadata.

Typical areas of application

Investigation of the origin and integrity of the images used
Identification of malware in container images
Reconstruction of the application state at a specific point in time
Check for unauthorised modifications to base images
Incident Response on Linux Systems
Judicial and non-judicial expert reports

How a Docker image analysis works

Once the image in question has been backed up, its individual layers are extracted and examined for any files, software and configurations they contain. Any available metadata regarding the image’s origin is cross-checked against documented or expected sources.

Why is Docker image analysis relevant to forensic investigations?

An image that has been tampered with or obtained from an untrusted source may contain malware even before the container is actually executed, which is why image analysis constitutes a distinct area of forensic investigation.

As an image may still be present locally or in a registry even after the associated container has been removed, analysing it can sometimes provide insights that would no longer be possible based on the container alone.

Frequently Asked Questions

What is the difference between an image and a container?+
An image is the immutable template from which a runnable, mutable container is created at start-up.
Can subsequent alterations to an image be detected?+
With the appropriate checksum and signature methods, as well as a detailed layer analysis, this is possible in many cases.
Are images from public registries also examined?+
Yes, where relevant, images obtained from public sources are also checked for known vulnerabilities or tampering.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of Docker images"? LanCologne can assist you with the court-admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.

Get in touch now