IT Forensics · Linux

Forensic analysis of Docker volumes – Forensic examination of persistent container data

Docker volumes are used for the persistent storage of data that is intended to be retained beyond the lifecycle of an individual container, such as database contents or application data.

Enquire without obligation

Whilst the writable container layer is lost when a container is removed, data stored in volumes is generally preserved and can still be subjected to forensic analysis even after the associated container has been terminated.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We back up and analyse Docker volumes, including the application data they contain, and map them to the relevant containers and applications in order to reconstruct incidents in a traceable manner.

Typical areas of application

Backing up persistent data after a container has been removed
Analysis of database contents in containerised applications
Evidence of unauthorised access to stored application data
Reconstruction of data changes within a volume
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how a Docker volume analysis works

Once the relevant volumes have been identified, their contents are forensically backed up. The data they contain is then analysed in a structured manner and, where possible, linked to the containers and applications that originally accessed them, in chronological order.

Why is Docker volume analysis relevant from a forensic perspective?

As volumes often contain the actual, economically relevant application data – such as customer databases – their forensic backup and analysis are of crucial importance in many incidents.

Unlike the ephemeral container layer, volume data persists even after the container has been removed, which is why it often represents the most robust source of data available for subsequent forensic investigation.

Frequently Asked Questions

Is volume data retained after a container has been deleted?+
Yes, provided that the volume itself has not also been removed, the data stored on it will remain intact, regardless of the container.
Can several containers access the same volume?+
Yes, this is a common scenario, which is taken into account accordingly when attributing access events in a forensic context.
How is volume data backed up for forensic purposes?+
By creating a complete, verifiable copy of the files contained on the volume, whilst maintaining the chain of custody.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of Docker volumes"? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.

Get in touch now