IT Forensics · Linux

Forensic analysis of Podman containers – Forensic investigation of daemonless container environments

Unlike Docker, Podman adopts a daemonless architectural approach, whereby containers can be run directly under the respective user account, which also affects the storage locations and permissions context of relevant artefacts.

Enquire without obligation

In particular, the ability to run containers entirely without root privileges in what is known as ‘rootless’ mode results in user-specific data structures, which must be taken into account accordingly when performing a forensic backup.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We secure and analyse Podman container environments, taking into account the respective execution context, and use this to reconstruct configurations, runtime data and usage histories.

Typical areas of application

Investigation into compromised Podman containers
Analysis of rootless container environments
Reconstruction of the container runtime history
Distinguishing between user-specific and system-wide container instances
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how a Podman analysis works

Once the backup has been completed, both system-wide and user-specific Podman data structures running in rootless mode are recorded. Container configurations and available logs are then checked for anomalies and timestamped.

Why is the Podman analysis relevant from a forensic perspective?

Rootless operation can result in container-related artefacts being stored in unexpected, user-specific locations, which can easily be overlooked during an investigation without the relevant specialist knowledge.

As Podman is increasingly being used as an alternative to Docker, particularly in security-sensitive environments, its forensically sound analysis is becoming increasingly important in practice.

Frequently Asked Questions

What is the fundamental difference between Podman and Docker?+
Podman does not require a background service running continuously and can run containers entirely without root privileges.
Where are Podman container data stored in rootless mode?+
Usually in the user’s home directory, which must be taken into account when performing a forensic backup.
Are Docker and Podman images compatible?+
Podman is largely compatible with Docker images and uses similar standard formats.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic analysis of Podman containers"? LanCologne can assist you with the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.

Get in touch now