Docker is just a container so all processes will show up in a simple pslist (pstree etc) for any queries running on the host itself.
The other cool thing about docker is that the container filesystem consists of an overlay which is mapped on top of the image - so if you search files (e.g. use the file finder artifact) in the docker directory (on linux this is /var/lib/docker/volumes ) you can see additional files that were added on top of the image. If the container is popped this will just show the new files (it is a diff basically from the current container state and the image). So this makes it really easy to focus on the new files and triage few files instead of an entire OS).
The directory structure is the /var/lib/docker is pretty interesting as well and you can figure out how the containers and layer relate to each other pretty easily.
So in the end it is all just files and processes - so use file finder, pstree etc
Thanks
Mike
| Mike Cohen Digital Paleontologist, Velocidex Enterprises |
| | | | |
|
|