Forensic Analysis of Podman Container Towards Metasploit Backdoor Using Checkpointctl
Hafiidh Akbar Sya'bani, Chaerul Umam, Lekso Budi Handoko · Inform Jurnal Ilmiah Bidang Teknologi Informasi dan Komunikasi · 2024
Container systems are a virtualization technology with an isolated environment. The isolated environment in a container system does not make cyber attacks impossible. In this research, containers where a cyber incident occurred, were forensically tested on the container's memory to obtain digital evidence. The forensic process uses standards from the NIST framework with collection, examination, analysis, and reporting stages. The forensic process begins by checking the container to obtain information from the container's memory. When the checkpoint procedure is executed in Podman, it is performed on one of the containers. This process produces a file in the.tar.gz format containing the container's information. After completing the checkpoint process, forensics is done by reading the checkpoint file using a checkpointctl tool. Forensic results showed that the container ran a malicious program as a backdoor with a PHP extension.