Back to CRIU
GSoC 2026

Forensic Checkpointing Framework for Kubernetes

In Kubernetes, container termination during security incidents results in the loss of critical forensic data. This project automates the capture of container states by building an event-driven pipeline. Using Falco for detection, a custom Kubernetes Controller for CRIU checkpointing, and checkpointctl for automated analysis, this project extends the capabilities of the existing Medusa framework and ensures that volatile evidence (such as memory, process trees, and open files) is preserved and reported. This enables forensic investigators to perform deep forensic analysis on frozen container states, which otherwise might have been ephemeral.

Project details

Contributor

Shailja Shaktawat

Mentors

Not available

Technologies

Not listed in the archive