Uploaded August 2026 | Updated September 2026, 2 weeks ago
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Shanghai, China (8-9 September, 2026) and Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
Container Forensics for Kubernetes: Building an Evidence Pipeline With Open Source Tools - Jie Wu & Pulkit Garg, Shopify
Your container just got compromised. But Kubernetes is ephemeral by design: the pod restarts in 30 seconds, and when it does, the memory, processes, and ephemeral filesystem are gone. How do you investigate something that no longer exists?
The cloud native ecosystem has gotten good at prevention and detection, but once an alert fires, actually figuring out what happened is still a gap.
This session walks through a forensics pipeline we built from open source tools, with a live demo of a simulated attack. Falco detects suspicious activity, Falco Talon automatically captures syscalls and network traffic, and we analyze the evidence in StratoShark, a Wireshark-style tool for system calls. We'll also show how the Kubernetes Checkpoint API can freeze container runtime state for offline inspection.
Attendees will walk away knowing how to set up automated evidence capture with Falco Talon, analyze captures in StratoShark, and trigger forensic checkpoints in their clusters.
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Shanghai, China (8-9 September, 2026) and Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
Container Forensics for Kubernetes: Building an Evidence Pipeline With Open Source Tools - Jie Wu & Pulkit Garg, Shopify
Your container just got compromised. But Kubernetes is ephemeral by design: the pod restarts in 30 seconds, and when it does, the memory, processes, and ephemeral filesystem are gone. How do you investigate something that no longer exists?
The cloud native ecosystem has gotten good at prevention and detection, but once an alert fires, actually figuring out what happened is still a gap.
This session walks through a forensics pipeline we built from open source tools, with a live demo of a simulated attack. Falco detects suspicious activity, Falco Talon automatically captures syscalls and network traffic, and we analyze the evidence in StratoShark, a Wireshark-style tool for system calls. We'll also show how the Kubernetes Checkpoint API can freeze container runtime state for offline inspection.
Attendees will walk away knowing how to set up automated evidence capture with Falco Talon, analyze captures in StratoShark, and trigger forensic checkpoints in their clusters.










