SlideShare a Scribd company logo
DFIR using Docker Containers
Incident Management on the go - Deep Shankar Yadav
#root@charlie~:whoami
#root@charlie~:whoami
• DFIR Practitioner
• Red Team Penetration Tester
• Security Analyst by Day; Ninja by Night
• Disaster Recovery Manager at n|u OWASP Delhi
DISCLAIMERS
• Registered brands belong to their respective
owners.
• The information provided in this presentation is a
results of a proper internet search.
• No content in this presentation violates any
copyright or intellectual property.
• What I am Gonna do ?
Agenda
• What is DFIR?
• What is Docker?
• Why use Docker ?
• What can be used ?
• How to use
What is DFIR?
DFIR using Docker Containers by Deep Shankar Yadav
DFIR using Docker Containers by Deep Shankar Yadav
DFIR using Docker Containers by Deep Shankar Yadav
DFIR using Docker Containers by Deep Shankar Yadav
DFIR using Docker Containers by Deep Shankar Yadav
Yes Sweety it’s all about it
Recipe for Successful DFIR Practices
What is Docker?
What is Docker?
What is Docker?
VM vs Docker
Why Docker?
• Isolation
• Lightweight
• Simplicity
• Workflow
• Community Support
Docker Community
• 1500+ Contributors
• 100,000+ Dockerized Applications
• 3 to 4 Million Developers using Docker
• 300+ Million Downloads
• 35,000 Docker related projects
• 70% enterprises are using docker
DFIR using Docker Containers by Deep Shankar Yadav
DOCKER ENGINE
• DOCKER DAEMON
• DOCKER CLI
DOCKER DAEMON
• Builds Images
• Runs and Manages Containers
• RESTful API
Docker CLI
Docker Hub
What Applications can be used?
All of them (CLI and Web Interfaces)
What are we going to see today
DFIR using Docker Containers by Deep Shankar Yadav
How to run images?
1. FIR: docker run -it -p 8000:8000 fir
2. CyberChef: docker run -d -p 2142:80 remnux/cyberchef
3. COMODO: docker run --rm -v !/null:/malware:ro malice/comodo <filename>
4. Malcom: docker run -p 2215:8080 -d --name malcom tomchop/malcom-automatic
5. Evolve: docker run --rm -it -v ~/null:/home/nonroot/memdumps -p 1337:8080 wzod/evolve bash
6. Volatility: docker run --rm -it -v ~/null:/home/nonroot/memdumps remnux/volatility bash
7. Mastiff: docker run --rm -it -v ~/null:/home/nonroot/workdir remnux/mastiff
8. Maltrive: docker run --rm -it -v ~/null:/archive remnux/maltrieve
9. Jsdetox: docker run --rm -p 3000:3000 remnux/jsdetox
10. PEScanner: docker run --rm -it -v ~/null:/home/nonroot/workdir remnux/pescanner bash
Charlie, You
have been
awesome; can I
make sandwich
for you ?
Any Questions Except?
Need more details?
Keep an eye on my blog
https://www.deepshankaryadav.net
Contact Details
Twitter @TheDeepSYadav
E-mail : - mail@deepshankaryadav.com
Web: https://www.deepshankaryadav.com
DFIR using Docker Containers by Deep Shankar Yadav
References
• https://www.docker.com/
• https://www.google.com
• https://digital-forensics.sans.org/
• https://remnux.org/docs/containers/malwar
e-analysis/

More Related Content

What's hot (20)

PPTX
Hacking Tizen : The OS of Everything - Nullcon Goa 2015
Ajin Abraham
 
PPTX
Automated Security Analysis of Android & iOS Applications with Mobile Securit...
Ajin Abraham
 
PPT
iOS Hacking: Advanced Pentest & Forensic Techniques
Ömer Coşkun
 
PDF
Abusing, Exploiting and Pwning with Firefox Add-ons
Ajin Abraham
 
PDF
Our Brave Modular Future
Orchestrate
 
PDF
Nullcon Goa 2016 - Automated Mobile Application Security Testing with Mobile ...
Ajin Abraham
 
PDF
Sony robotics overview
Tomoya Fujita
 
PDF
Mwri security testing-android-with-mercury-2013-04-02
Droidcon Berlin
 
PPTX
iOS-Application-Security-iAmPr3m
Prem Kumar (OSCP)
 
PPTX
Mobile security part 2
Romansh Yadav
 
PPTX
Mobile security part 1(Android Apps Pentesting)- Romansh yadav
Romansh Yadav
 
PDF
ROS/ROS2 Distributed System with Kubernetes
Tomoya Fujita
 
PPTX
Hacking and securing ios applications
Satish b
 
ODP
Diving inside Android Wifi
Nanik Tolaram
 
PPTX
Hacking Samsung's Tizen: The OS of Everything - Hack In the Box 2015
Ajin Abraham
 
PDF
Flare - tech-intro-for-paris-hackathon
Cisco DevNet
 
PPTX
Penetrating Android Aapplications
Roshan Thomas
 
PDF
Serverless Security: What's Left To Protect
Guy Podjarny
 
PDF
Null Dubai Humla_Romansh_Yadav_Android_app_pentesting
Romansh Yadav
 
PDF
Ruxmon April 2014 - Introduction to iOS Penetration Testing
eightbit
 
Hacking Tizen : The OS of Everything - Nullcon Goa 2015
Ajin Abraham
 
Automated Security Analysis of Android & iOS Applications with Mobile Securit...
Ajin Abraham
 
iOS Hacking: Advanced Pentest & Forensic Techniques
Ömer Coşkun
 
Abusing, Exploiting and Pwning with Firefox Add-ons
Ajin Abraham
 
Our Brave Modular Future
Orchestrate
 
Nullcon Goa 2016 - Automated Mobile Application Security Testing with Mobile ...
Ajin Abraham
 
Sony robotics overview
Tomoya Fujita
 
Mwri security testing-android-with-mercury-2013-04-02
Droidcon Berlin
 
iOS-Application-Security-iAmPr3m
Prem Kumar (OSCP)
 
Mobile security part 2
Romansh Yadav
 
Mobile security part 1(Android Apps Pentesting)- Romansh yadav
Romansh Yadav
 
ROS/ROS2 Distributed System with Kubernetes
Tomoya Fujita
 
Hacking and securing ios applications
Satish b
 
Diving inside Android Wifi
Nanik Tolaram
 
Hacking Samsung's Tizen: The OS of Everything - Hack In the Box 2015
Ajin Abraham
 
Flare - tech-intro-for-paris-hackathon
Cisco DevNet
 
Penetrating Android Aapplications
Roshan Thomas
 
Serverless Security: What's Left To Protect
Guy Podjarny
 
Null Dubai Humla_Romansh_Yadav_Android_app_pentesting
Romansh Yadav
 
Ruxmon April 2014 - Introduction to iOS Penetration Testing
eightbit
 

Viewers also liked (18)

PDF
OWASP Top 10 2013
markstory
 
PPTX
IoT Security Risks and Challenges
OWASP Delhi
 
PDF
How to find Zero day vulnerabilities
Mohammed A. Imran
 
PPTX
RAT - Kill or Get Killed! by Karan Bansal
OWASP Delhi
 
PPTX
Quantum Computing by Rajeev Chauhan
OWASP Delhi
 
PPT
Darknets - Introduction & Deanonymization of Tor Users By Hitesh Bhatia
OWASP Delhi
 
PDF
Null Singapore 2015 accomplishments
Mohammed A. Imran
 
PPTX
Pwning with XSS: from alert() to reverse shell: Defcon Banglore 2013
Ajin Abraham
 
ODP
Hostile Subdomain Takeover by Ankit Prateek
OWASP Delhi
 
PPTX
A2 - broken authentication and session management(OWASP thailand chapter Apri...
Noppadol Songsakaew
 
PPTX
OWASP top 10-2013
tmd800
 
PDF
Thwarting The Surveillance in Online Communication by Adhokshaj Mishra
OWASP Delhi
 
PPTX
Owasp Top 10 A1: Injection
Michael Hendrickx
 
PDF
OWASP ASVS と Cheat Sheet シリーズ (日本語版) のご紹介 (OSC2016Hokkaido)
JPCERT Coordination Center
 
PDF
Owasp Project を使ってみた
Akitsugu Ito
 
PDF
Orkneynewstoday
Jack740
 
DOC
Gajendra_Resume1
Gajendra H S
 
PDF
Repair home
Jack740
 
OWASP Top 10 2013
markstory
 
IoT Security Risks and Challenges
OWASP Delhi
 
How to find Zero day vulnerabilities
Mohammed A. Imran
 
RAT - Kill or Get Killed! by Karan Bansal
OWASP Delhi
 
Quantum Computing by Rajeev Chauhan
OWASP Delhi
 
Darknets - Introduction & Deanonymization of Tor Users By Hitesh Bhatia
OWASP Delhi
 
Null Singapore 2015 accomplishments
Mohammed A. Imran
 
Pwning with XSS: from alert() to reverse shell: Defcon Banglore 2013
Ajin Abraham
 
Hostile Subdomain Takeover by Ankit Prateek
OWASP Delhi
 
A2 - broken authentication and session management(OWASP thailand chapter Apri...
Noppadol Songsakaew
 
OWASP top 10-2013
tmd800
 
Thwarting The Surveillance in Online Communication by Adhokshaj Mishra
OWASP Delhi
 
Owasp Top 10 A1: Injection
Michael Hendrickx
 
OWASP ASVS と Cheat Sheet シリーズ (日本語版) のご紹介 (OSC2016Hokkaido)
JPCERT Coordination Center
 
Owasp Project を使ってみた
Akitsugu Ito
 
Orkneynewstoday
Jack740
 
Gajendra_Resume1
Gajendra H S
 
Repair home
Jack740
 
Ad

Similar to DFIR using Docker Containers by Deep Shankar Yadav (20)

PPTX
Dockerize the World - presentation from Hradec Kralove
damovsky
 
PDF
Docker puebla bday #4 celebration
Ramon Morales
 
PPTX
Docker, how to use it. organize a meeting with IBM products...
Andrea Fontana
 
PDF
5GCroCo_DockerSecurityBasics_Training.pdf
MaghsoudAbbasPour1
 
PDF
DCEU 18: Building Your Development Pipeline
Docker, Inc.
 
PDF
Faster and Easier Software Development using Docker Platform
msyukor
 
PPTX
Dockerize the World
damovsky
 
PDF
Docker 101: An Introduction
POSSCON
 
PDF
Clustering Docker with Docker Swarm on openSUSE
Saputro Aryulianto
 
PPTX
Introduction to Docker
Google Developer Group Zürich
 
PDF
Docker in pratice -chenyifei
dotCloud
 
PDF
Docker workshop
Rafael Dutra
 
PDF
Containers without docker | DevNation Tech Talk
Red Hat Developers
 
PPTX
Docker Security
antitree
 
PPTX
Docker for the new Era: Introducing Docker,its components and tools
Ramit Surana
 
PDF
DCA. certificate slide Session 1
Hadi Tayanloo
 
PDF
Docker Mentor Week 2016 - Medan
Albert Suwandhi
 
PDF
Docker introduction
Jo Ee Liew
 
PPTX
Evotalks Docker Presentation
Denis - Florin Rendler
 
PPTX
Docker Timisoara: Dockercon19 recap slides, 23 may 2019
Radulescu Adina-Valentina
 
Dockerize the World - presentation from Hradec Kralove
damovsky
 
Docker puebla bday #4 celebration
Ramon Morales
 
Docker, how to use it. organize a meeting with IBM products...
Andrea Fontana
 
5GCroCo_DockerSecurityBasics_Training.pdf
MaghsoudAbbasPour1
 
DCEU 18: Building Your Development Pipeline
Docker, Inc.
 
Faster and Easier Software Development using Docker Platform
msyukor
 
Dockerize the World
damovsky
 
Docker 101: An Introduction
POSSCON
 
Clustering Docker with Docker Swarm on openSUSE
Saputro Aryulianto
 
Introduction to Docker
Google Developer Group Zürich
 
Docker in pratice -chenyifei
dotCloud
 
Docker workshop
Rafael Dutra
 
Containers without docker | DevNation Tech Talk
Red Hat Developers
 
Docker Security
antitree
 
Docker for the new Era: Introducing Docker,its components and tools
Ramit Surana
 
DCA. certificate slide Session 1
Hadi Tayanloo
 
Docker Mentor Week 2016 - Medan
Albert Suwandhi
 
Docker introduction
Jo Ee Liew
 
Evotalks Docker Presentation
Denis - Florin Rendler
 
Docker Timisoara: Dockercon19 recap slides, 23 may 2019
Radulescu Adina-Valentina
 
Ad

More from OWASP Delhi (20)

PDF
Getting Started With Hacking Android & iOS Apps? Tools, Techniques and resources
OWASP Delhi
 
PDF
Securing dns records from subdomain takeover
OWASP Delhi
 
PDF
Effective Cyber Security Report Writing
OWASP Delhi
 
PPTX
Data sniffing over Air Gap
OWASP Delhi
 
PPTX
UDP Hunter
OWASP Delhi
 
PDF
Demystifying Container Escapes
OWASP Delhi
 
PPTX
Automating WAF using Terraform
OWASP Delhi
 
PPTX
Actionable Threat Intelligence
OWASP Delhi
 
PDF
Threat hunting 101 by Sandeep Singh
OWASP Delhi
 
PPTX
Owasp top 10 vulnerabilities
OWASP Delhi
 
PPTX
Recon with Nmap
OWASP Delhi
 
PPTX
Securing AWS environments by Ankit Giri
OWASP Delhi
 
PDF
DMARC Overview
OWASP Delhi
 
PDF
Cloud assessments by :- Aakash Goel
OWASP Delhi
 
PDF
Pentesting Rest API's by :- Gaurang Bhatnagar
OWASP Delhi
 
ODP
Wireless security beyond password cracking by Mohit Ranjan
OWASP Delhi
 
PDF
IETF's Role and Mandate in Internet Governance by Mohit Batra
OWASP Delhi
 
PDF
Malicious Hypervisor - Virtualization in Shellcodes by Adhokshaj Mishra
OWASP Delhi
 
PPTX
ICS Security 101 by Sandeep Singh
OWASP Delhi
 
PDF
Network discovery - Inside out by Aakash Goel
OWASP Delhi
 
Getting Started With Hacking Android & iOS Apps? Tools, Techniques and resources
OWASP Delhi
 
Securing dns records from subdomain takeover
OWASP Delhi
 
Effective Cyber Security Report Writing
OWASP Delhi
 
Data sniffing over Air Gap
OWASP Delhi
 
UDP Hunter
OWASP Delhi
 
Demystifying Container Escapes
OWASP Delhi
 
Automating WAF using Terraform
OWASP Delhi
 
Actionable Threat Intelligence
OWASP Delhi
 
Threat hunting 101 by Sandeep Singh
OWASP Delhi
 
Owasp top 10 vulnerabilities
OWASP Delhi
 
Recon with Nmap
OWASP Delhi
 
Securing AWS environments by Ankit Giri
OWASP Delhi
 
DMARC Overview
OWASP Delhi
 
Cloud assessments by :- Aakash Goel
OWASP Delhi
 
Pentesting Rest API's by :- Gaurang Bhatnagar
OWASP Delhi
 
Wireless security beyond password cracking by Mohit Ranjan
OWASP Delhi
 
IETF's Role and Mandate in Internet Governance by Mohit Batra
OWASP Delhi
 
Malicious Hypervisor - Virtualization in Shellcodes by Adhokshaj Mishra
OWASP Delhi
 
ICS Security 101 by Sandeep Singh
OWASP Delhi
 
Network discovery - Inside out by Aakash Goel
OWASP Delhi
 

Recently uploaded (20)

PPTX
Optimization_Techniques_ML_Presentation.pptx
farispalayi
 
PPTX
英国假毕业证诺森比亚大学成绩单GPA修改UNN学生卡网上可查学历成绩单
Taqyea
 
PPT
Computer Securityyyyyyyy - Chapter 1.ppt
SolomonSB
 
PPTX
internet básico presentacion es una red global
70965857
 
PPTX
西班牙武康大学毕业证书{UCAMOfferUCAM成绩单水印}原版制作
Taqyea
 
PDF
AI_MOD_1.pdf artificial intelligence notes
shreyarrce
 
PPTX
L1A Season 1 Guide made by A hegy Eng Grammar fixed
toszolder91
 
PPTX
Presentation3gsgsgsgsdfgadgsfgfgsfgagsfgsfgzfdgsdgs.pptx
SUB03
 
PPT
introductio to computers by arthur janry
RamananMuthukrishnan
 
PPTX
PE introd.pptxfrgfgfdgfdgfgrtretrt44t444
nepmithibai2024
 
PPTX
Research Design - Report on seminar in thesis writing. PPTX
arvielobos1
 
PDF
Azure_DevOps introduction for CI/CD and Agile
henrymails
 
PPTX
unit 2_2 copy right fdrgfdgfai and sm.pptx
nepmithibai2024
 
PPTX
原版西班牙莱昂大学毕业证(León毕业证书)如何办理
Taqyea
 
PDF
𝐁𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓
hokimamad0
 
PPTX
ONLINE BIRTH CERTIFICATE APPLICATION SYSYTEM PPT.pptx
ShyamasreeDutta
 
PPTX
Cost_of_Quality_Presentation_Software_Engineering.pptx
farispalayi
 
PDF
DevOps Design for different deployment options
henrymails
 
PPTX
INTEGRATION OF ICT IN LEARNING AND INCORPORATIING TECHNOLOGY
kvshardwork1235
 
PPT
introduction to networking with basics coverage
RamananMuthukrishnan
 
Optimization_Techniques_ML_Presentation.pptx
farispalayi
 
英国假毕业证诺森比亚大学成绩单GPA修改UNN学生卡网上可查学历成绩单
Taqyea
 
Computer Securityyyyyyyy - Chapter 1.ppt
SolomonSB
 
internet básico presentacion es una red global
70965857
 
西班牙武康大学毕业证书{UCAMOfferUCAM成绩单水印}原版制作
Taqyea
 
AI_MOD_1.pdf artificial intelligence notes
shreyarrce
 
L1A Season 1 Guide made by A hegy Eng Grammar fixed
toszolder91
 
Presentation3gsgsgsgsdfgadgsfgfgsfgagsfgsfgzfdgsdgs.pptx
SUB03
 
introductio to computers by arthur janry
RamananMuthukrishnan
 
PE introd.pptxfrgfgfdgfdgfgrtretrt44t444
nepmithibai2024
 
Research Design - Report on seminar in thesis writing. PPTX
arvielobos1
 
Azure_DevOps introduction for CI/CD and Agile
henrymails
 
unit 2_2 copy right fdrgfdgfai and sm.pptx
nepmithibai2024
 
原版西班牙莱昂大学毕业证(León毕业证书)如何办理
Taqyea
 
𝐁𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓
hokimamad0
 
ONLINE BIRTH CERTIFICATE APPLICATION SYSYTEM PPT.pptx
ShyamasreeDutta
 
Cost_of_Quality_Presentation_Software_Engineering.pptx
farispalayi
 
DevOps Design for different deployment options
henrymails
 
INTEGRATION OF ICT IN LEARNING AND INCORPORATIING TECHNOLOGY
kvshardwork1235
 
introduction to networking with basics coverage
RamananMuthukrishnan
 

DFIR using Docker Containers by Deep Shankar Yadav