Container Forensics & Incident Response Solutions
Incident response and container forensics for Kubernetes
Watch On Demand! FIND, FOCUS, and FIX the Cloud Threats that Matter with Accenture, AWS, Expel, Snyk, Sysdig and SANS
Conduct forensics and incident response for containers and Kubernetes to understand security breaches, meet compliance requirements and recover quickly. Sysdig Secure is your source of truth for all activity in the container ecosystem before, during and after an incident.
Collect forensics data to understand
Leverage the Sysdig Secure depth of data within a detailed forensics report to quickly answer the questions of “when”, “what”, “who” and “why” for your incidents.
Determine what happened
Streamline incident response and quickly determine what happened with a detailed activity record. Fine-grained policies leverage the Falco rules library to analyze and audit runtime policy violations.
Conduct post mortem analysis
Analyze forensic captures and recreate all system activity, even for long-gone containers.
Understand and Contain the Impact of Any Container Security Incident
Curated Runtime Policies
Answering the “why” questions with container and Kubernetes incident response tools is particularly tricky in distributed, dynamic environments, especially with the ephemeral nature of containers. The incident response workflow within Sysdig Secure lets you define highly granular rules (leveraging Falco) to check for unexpected activities. You can use a flexible syntax to identify what happened (e.g., cryptojacking, sensitive information leak) and recognize root cause information (e.g., user compromise, vulnerability).
Faster Incident Response & Recovery with a Tailored Workflow
Security Event Timeline
When unusual activity is detected, the out-of-the-box Sysdig policies, based on Falco or your custom runtime policies, can trigger a security event automatically. When you see an incident, you can immediately zoom in and isolate it to a specific part of the Kubernetes infrastructure.
Real-Time Audit of User and System Activity
Sysdig Secure lets you filter by any field to view the real-time stream of user and system activities. These activities are correlated with metrics across the stack to identify the root cause of security incidents faster (Kubernetes, container, host, network, and files). Sysdig Secure gives you the ability to trace a kube-exec through to user and network activity.
Go deep and see what the malicious actor did. This example shows they executed bash, then curl commands, to download a file from the Internet, decompress and shred the bash history.
In-Depth Post Mortem Analysis of the Container
Rich Forensics Data
Containers terminate long before container incident response and forensics begin, so Sysdig Secure saves forensics data while containers are still active. Via a SCAP file, container forensic captures provide the ability to investigate, analyze and recreate activity associated with security events before, during and after the incident.
You May Also Be Interested In
-
Runtime Security
Learn More
-
Container Forensics
Learn More
-
Image Scanning
Learn More
-
Sysdig Secure
Learn More
Resources