IT Forensics · Linux

Forensic analysis of LXC/LXD containers – conducting a forensically traceable examination of system containers

LXC and LXD, which is based on it, take a more system-oriented approach than traditional application containers and emulate complete, lightweight Linux system environments within a single kernel.

Enquire without obligation

Owing to this closeness to the underlying system, LXC/LXD containers often resemble a complete Linux system in their internal structure; consequently, many traditional methods of Linux system forensics are applied when analysing them.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We secure and analyse LXC/LXD container file systems and associated configurations, applying established methods of Linux system forensics to the respective container environment.

Typical areas of application

Investigation of compromised system containers
Reconstruction of a container’s internal usage history
Analysis of cross-container configurations
Distinguishing between host- and container-specific findings
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how an LXC/LXD analysis works

Once the container file system and the associated configuration have been backed up, the environment is examined in the same way as a complete Linux system. Container-specific configuration files are also checked for any anomalies.

Why is LXC/LXD analysis relevant in a forensic context?

As LXC/LXD containers often represent complete system environments with their own services and user accounts, an investigation within a single container may require a level of complexity similar to that of a standalone system.

The fact that the host kernel is shared also means that certain vulnerabilities could, in theory, affect multiple containers, a factor which is taken into account during the forensic assessment.

Frequently Asked Questions

What is the difference between LXC/LXD and Docker?+
LXC/LXD provide full Linux environments that are closely integrated with the host system, whilst Docker primarily provides containers designed for individual applications.
Can an LXC container be examined as if it were a standalone system?+
To a large extent, yes, as the internal structure of an LXC container closely resembles that of a traditional Linux file system.
Are LXD’s snapshot functions also taken into account?+
Yes, where available, LXD snapshots can provide valuable historical states of a container.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of LXC/LXD containers"? LanCologne can assist you with the legally admissible preservation of digital evidence and the transparent analysis of relevant Linux artefacts.

Get in touch now