Sign inSign up

nanobug8/cfak

By nanobug8

•Updated 9 months ago

It is designed to run as an ephemeral task on AWS Fargate.

Image
Security
0

694

nanobug8/cfak repository overview

⁠C-FAK: Cloud Forensic Acquisition Kit

Status Platform

C-FAK is a forensic acquisition controller designed to run as an ephemeral task on AWS Fargate.

Its role is to orchestrate volatile memory acquisition from target EC2 instances using AWS Systems Manager (SSM).

The container includes the memory acquisition tools:

  • AVML for Linux
  • WinPMEM for Windows

When executed, the controller:

  1. Receives the target EC2 instance ID.
  2. Uploads the acquisition tools to an S3 staging location.
  3. Detects whether the target is Linux or Windows.
  4. Uses AWS SSM to instruct the target instance to download and execute the appropriate tool.
  5. Monitors the remote acquisition process.
  6. The target EC2 uploads the resulting memory image directly to the configured S3 evidence bucket.

The memory acquisition itself does not run inside the Fargate container. AVML or WinPMEM executes locally on the target EC2 instance.

S3 is also used as a staging location to distribute the forensic acquisition binaries to the target instances.

The controller relies on AWS IAM roles and connectivity to the EC2, SSM, and S3 APIs. No direct SSH connection to the target EC2 instance is required.

Tag summary

Content type

Image

Digest

sha256:1a248d4cc…

Size

84.8 MB

Last updated

9 months ago

docker pull nanobug8/cfak