IT Forensics · Linux
Forensic analysis of LXC/LXD containers – conducting a forensically traceable examination of system containers
LXC and LXD, which is based on it, take a more system-oriented approach than traditional application containers and emulate complete, lightweight Linux system environments within a single kernel.
Owing to this closeness to the underlying system, LXC/LXD containers often resemble a complete Linux system in their internal structure; consequently, many traditional methods of Linux system forensics are applied when analysing them.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We secure and analyse LXC/LXD container file systems and associated configurations, applying established methods of Linux system forensics to the respective container environment.
Typical areas of application
This is how an LXC/LXD analysis works
Once the container file system and the associated configuration have been backed up, the environment is examined in the same way as a complete Linux system. Container-specific configuration files are also checked for any anomalies.
Why is LXC/LXD analysis relevant in a forensic context?
As LXC/LXD containers often represent complete system environments with their own services and user accounts, an investigation within a single container may require a level of complexity similar to that of a standalone system.
The fact that the host kernel is shared also means that certain vulnerabilities could, in theory, affect multiple containers, a factor which is taken into account during the forensic assessment.
Frequently Asked Questions
LanCologne – Linux Forensics Cologne
Do you require a professional forensic investigation into „forensic analysis of LXC/LXD containers"? LanCologne can assist you with the legally admissible preservation of digital evidence and the transparent analysis of relevant Linux artefacts.
Related to this topic
- Forensic analysis of KVM/QEMU virtualisation – Forensic examination of virtual machines running on Linux
- Forensic analysis of VMware on Linux – Investigating VMware virtualisation environments on Linux
- Forensic analysis of VirtualBox on Linux – Forensic examination of VirtualBox environments on Linux
- Forensic analysis of Cloud Init configuration – Forensic investigation of automated system initialisation