Investigating Security Incidents with Forensic Snapshots in Kubernetes
- Track: Open Source Digital Forensics
- Room: UB4.132
- Day: Sunday
- Start: 11:00
- End: 11:30
- Video only: ub4132
- Chat: Join the conversation!
The absence of forensics data can be just as dangerous as the presence of malicious activity. While traditional digital forensics focuses on artefacts located on storage devices, containerized environments like Kubernetes introduce new challenges for collection of digital evidence from compromised applications, where malware now routinely leaves no traces. In this talk, we are going to explore how to collect, preserve, and analyse forensic snapshots with transparent checkpointing methods while maintaining a chain of custody to investigate security incidents. We will also discuss techniques for automation in real-world scenarios and best practices for capturing and analysing malicious activity in compromised containers.
Speakers
| Adrian Reber | |
| Radostin Stoyanov | |
| Lorena Goldoni |