// artifact family

container / orchestration expansion

23 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.

tools
23
catalog slugs
23
processing
local · in browser

tools in this family

ordered as in the forensics catalog. every tool runs locally — no upload, no account.

  1. aks audit log forensic analyzerdrop aks audit log · parse api + admin events
  2. argocd audit log forensic analyzerdrop argocd audit log · parse gitops sync events
  3. buildah build log forensic analyzerdrop buildah build log · parse layer build sequence
  4. container registry pull log forensic analyzerdrop generic oci registry pull log · parse image pulls + originating ip
  5. containerd runtime state forensic analyzerdrop containerd state dir + log · parse container lifecycle events
  6. cri o runtime log forensic analyzerdrop cri-o log · parse pod lifecycle
  7. eks audit log forensic analyzerdrop eks control-plane audit log · parse api events
  8. flux cd audit log forensic analyzerdrop flux controller log · parse reconciliation events
  9. gke audit log forensic analyzerdrop gke audit log · parse api + admin events
  10. harbor registry audit log forensic analyzerdrop harbor audit log · parse image push/pull/scan events
  11. hashicorp consul audit log forensic analyzerdrop consul audit log · parse kv + service events
  12. hashicorp nomad job log forensic analyzerdrop nomad job log · parse allocation events
  13. hashicorp vault audit log forensic analyzerdrop vault audit json · parse secret access + lease events
  14. k3s audit log forensic analyzerdrop k3s audit log · parse api server events
  15. kubernetes privilege escalation detectordrop k8s audit log · detect role/clusterrole escalation patterns
  16. kubernetes secret exfil pattern detectordrop k8s audit log · detect mass secret reads + token usage anomalies
  17. kubernetes service account token abuse detectordrop k8s audit log · detect sa token usage from unexpected pods
  18. lxc lxd container forensic analyzerdrop lxc/lxd storage pool · parse container snapshots + config
  19. microk8s audit log forensic analyzerdrop microk8s audit log · parse api events
  20. openshift audit log forensic analyzerdrop openshift audit log · parse api + project events
  21. podman container artifact forensic extractordrop podman rootful/rootless storage · parse containers + images + volumes
  22. rancher audit log forensic analyzerdrop rancher audit log · parse multi-cluster admin events
  23. spinnaker audit log forensic analyzerdrop spinnaker audit log · parse pipeline + stage events
ready