GSoC 2026
Forensic Checkpointing Framework for Kubernetes
In Kubernetes, container termination during security incidents results in the loss of critical forensic data. This project automates the capture of container states by building an event-driven pipeline. Using Falco for detection, a custom Kubernetes Controller for CRIU checkpointing, and checkpointctl for automated analysis, this project extends the capabilities of the existing Medusa framework and ensures that volatile evidence (such as memory, process trees, and open files) is preserved and reported. This enables forensic investigators to perform deep forensic analysis on frozen container states, which otherwise might have been ephemeral.
Project details
Technologies
Not listed in the archive