Example report

Docker Desktop Installer.exe

product
Docker Desktop 4.38.0
vendor
Docker Inc.
source
Endpoint agent, CON-WKS-4471
assayed
2026-08-03 09:43:07Z
duration
1m 45s
Lens

Or define your ownSection membership is configurable. These three are starting points.

Showing 3 of 18 sectionsShowing 11 of 18 sectionsShowing 18 of 18 sections

Summary readings for this artifact
allow87/ 100B88 / 100verified
verdictfile trustvendor riskattribution
confidence high, risk low5 weighted factorsidentity verifiedcontent-derived

Verdict

Signed by a verified publisher, matching the declared product and version. No malicious signals in any content path that was examined. Two items below need a policy decision rather than a security one.

Key findings

  • Authenticode signature valid and chains to a publicly trusted root. Subject matches the vendor identified from artifact content, not from the filename or the declared product string.
  • Installs four additional executables that run as services or long-lived processes. Each is inventoried separately in Composition; they are the components that appear in an endpoint register with no catalog entry of their own.
  • Requests elevation and installs machine-wide. This is expected for this product and is stated here because the approval decision depends on it.
  • Bundles a Kubernetes distribution and a container runtime. Both are governed software in their own right and are not covered by an approval of the parent product.

Recommended actions

  1. Before approvalDecide whether the bundled container runtime and Kubernetes distribution are separately approved, or covered by this approval. They are listed individually in Composition.
  2. Before approvalConfirm the licence position. Docker Desktop requires a paid subscription above a company size and headcount threshold: this is a commercial obligation, not a technical one.
  3. On deploymentAdd the four bundled executables to the sanctioned register so they do not surface as unattributed binaries in endpoint inventory.
  4. OngoingThis product self-updates. Re-analysis on version change is the only way the approval stays accurate.
Decision4Why it concluded that, and whether to approve

Verdict factors

factorreadingweightdetail
Code signaturepositivehighValid Authenticode chain, countersigned timestamp, subject corroborated against certificate transparency and company registration.
Malicious signalspositivehighNo rule matches in any examined content path. See Analysis coverage for what was and was not examined.
Vendor reputationpositivemediumIdentity verified against two independent registries plus certificate transparency. No single feed drove this.
Software categoryneutralmediumDeveloper tooling with container runtime capability. Elevated baseline risk by category, not by finding.
Licence obligationsattentionmediumCommercial subscription threshold applies. A policy question, not a security one.
Terms-of-service postureneutrallowStandard commercial terms. Telemetry is on by default and configurable.

Scores

87/ 100 file trust

dimensionweightscorenote
Malicious signals40%100No matches in examined paths
Code signing20%100Valid chain, timestamped
Vendor reputation20%92Verified identity, mature publisher
Software category15%45Container runtime, elevated baseline
Terms-of-service posture5%70Telemetry default-on
Vendor2Who published this, and what corroborates it

Vendor intelligence

B88 / 100 vendor risk · identity verified · evidence completeness 92%

Identity confidence is graded, not asserted. Every line below is tied to something in the artifact itself: a certificate subject, a declared product string, because a package name is not a vendor.

dimensionweightscorenote
Identity verification25%100Registration and certificate subject agree
Security posture25%78Published advisory process; no unresolved disclosures found
Code signing15%100Consistent signing across releases examined
Licence compliance15%80Clear terms; commercial threshold applies
Community health10%95Active public repositories, frequent releases
Vendor maturity10%90Established, funded, long operating history

Evidence

sourcetied tosays
Certificate subjectThe signature on this artifactDocker Inc., US
Company registrationSubject name and jurisdiction from the certificateActive registration matching the certificate subject
Certificate transparencyDomains in the certificate subjectLong-lived issuance history, no anomalies
Public repositoriesProduct name declared in the artifact version resourceMaintained, releases align with the declared version

Enterprise readiness

Deployment methodMachine-wide installer, elevation required
Silent installSupported
Update mechanismSelf-updating, in-product
UninstallRegisters an uninstall entry
Runs as serviceYes, four components
Network listenersLocal sockets and a named pipe
TelemetryOn by default, configurable
Offline operationPartial, image pulls require network

Approval readiness

Approve with conditions

Conditions

  • Bundled components approved separately or explicitly covered
  • Licence threshold confirmed against current headcount
  • Re-analysis on version change

Rules matched

Signed by verified publisherallow
Minimum trust score ≥ 70allow
Category: container runtimereview
Commercial licence thresholdreview
Compliance3Framework posture, obligations, and the limits

Compliance

frameworkmetgapreview
NIST SP 800-53602
SOC 2401
ISO 27001:2022 A.8501
CMMC 2.0301
PCI-DSS v4.0201
HIPAA Security Rule200
GDPR101

Controls

controlstatusnote
CM-7Least functionalityNIST SP 800-53reviewBundled runtime expands installed functionality beyond the approved product
CM-11User-installed softwareNIST SP 800-53metMachine-wide install; governed by policy
SI-7Software integrityNIST SP 800-53metSignature verified, chain intact
SA-12Supply chain protectionNIST SP 800-53reviewFour bundled components require their own provenance record
CC6.8Unauthorised softwareSOC 2metApproval decision recorded with evidence
CC7.1Change detectionSOC 2reviewSelf-updating product; detection depends on re-analysis
A.8.19Software on operational systemsISO 27001:2022 A.8metInstall path and method recorded
A.8.30Outsourced developmentISO 27001:2022 A.8reviewBundled third-party components present

Licence obligations

Commercial, with a free tier bounded by company size

obligationappliesnote
Commercial-use restrictionyesPaid subscription required above the vendor’s stated company size and revenue threshold
AttributionyesThird-party notices bundled with the product
CopyleftnoNo copyleft obligation on the parent artifact
Source disclosurenoNot triggered by use as distributed
Patent grantyesApache-2.0 components carry an express grant

Analysis coverage

What was examined, and what was not. The limits belong next to the decision, not behind it.

Examined

PE structure, sections, imports, resourcesfull
Authenticode signature and certificate chainfull
NSIS installer script and embedded payload listingfull
Bundled executables, headers, signatures, identityfull
Rule matching across extracted contentfull

Not examined

Runtime behaviourStatic analysis only. Nothing here describes what the installer does when executed.
Container images pulled after installationFetched at runtime from a registry. Not present in the artifact and not analysed.
Multi-engine antivirus verdictsMulti-engine antivirus runs on a customer-supplied key by design: the quota and the data-sharing decision stay with you rather than with us. No key is attached to this example, so no engines were consulted.
Advisory and vulnerability statusNot assessed. This report describes what the file is and who made it, not what is known to be wrong with the software.
Anything requiring the installer to be executedNo sandbox detonation was performed. Every statement in this report is derived from the artifact as it sits on disk.
Composition4What it is made of, and what identifies it

File overview

TypePE32+ executable (GUI) x86-64, NSIS installer
FamilyWindows installer
Size618.4 MB
Submitted2026-08-03T09:41:22Z
Completed2026-08-03T09:43:07Z

File identifiers

SHA-256e3b4c1a97f28d6054b0f39aa71c8d25e6f4a0b93cc7e18d2fa5b60947e3c1d88
SHA-15f2a9c73e18b40d6ca27f9b3081de54a6c9f2b17
MD5a94f3c7d21b58e0946f7c3d81ab52e6f
TLSHT1F4A6B29C3E8047D5A1C6F03B95E2D871A4C0F63B8D95E2A07C4F1B36D8E5A092C7B04F

Names

Submitted asDocker Desktop Installer.exe
Original filenameDocker Desktop Installer.exe
Product nameDocker Desktop
Internal nameDocker Desktop Installer

Nearest in your own history

artifacttlsh distanceseen
Docker Desktop Installer.exe 4.37.2412026-06-14
Docker Desktop Installer.exe 4.36.0632026-04-02

Distances are against this tenant’s own history only. Nothing is compared across tenants.

Technical details

Machinex86-64
SubsystemWindows GUI
Compile timestamp2026-01-28T14:02:11Z
Sections6
Entry point section.text
OverlayPresent, 612.8 MB NSIS payload
Base relocationsPresent
ASLR / DEP / CFGEnabled / Enabled / Enabled

Sections

namecharacteristicsentropynote
.textCNT_CODE, MEM_EXECUTE, MEM_READ6.41Ordinary compiled code
.rdataCNT_INITIALIZED_DATA, MEM_READ5.02
.dataCNT_INITIALIZED_DATA, MEM_READ, MEM_WRITE3.88
.rsrcCNT_INITIALIZED_DATA, MEM_READ4.17Version resource, icons, manifest
.relocCNT_INITIALIZED_DATA, MEM_DISCARDABLE, MEM_READ5.64
.ndataCNT_UNINITIALIZED_DATA, MEM_READ, MEM_WRITE0.00NSIS working section, zero raw size, allocated at load

Imports

modulefunctionsnote
KERNEL32.dll84
USER32.dll31
ADVAPI32.dll19Service and registry APIs, consistent with an installer
SHELL32.dll12
ole32.dll7
COMCTL32.dll5

Signature

StatusValid
SubjectDocker Inc.
IssuerDigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Digest algorithmSHA-256
CountersignatureRFC 3161 timestamp, 2026-01-28T14:19:44Z
ChainTerminates in a publicly trusted root

Enrichment

sourceconsultedresult
Certificate transparencyyesIssuance history consistent with a long-lived publisher
Company registrationyesActive registration matching certificate subject
Verified vendor factsyesFounded, headquarters and parent company corroborated
Public repository healthyesActive, releases align with declared version
Known-malware hash intelligenceyesNo record for this hashAbsence of a record is not evidence of safety and does not contribute to the verdict.
Community threat-intelligence pulsesyesNo pulses reference this artifactNever sufficient on its own: a single uncorroborated feed does not drive a verdict in either direction.
Licence resolutionyesComponent licences resolved for 41 of 44 bundled components
Multi-engine antivirusnoNot consultedMulti-engine antivirus runs on your own vendor key by design: your quota, your data-sharing terms, not ours. That is a deliberate product decision rather than a limitation. No key is attached to this example, so no engines were consulted and no engine result appears anywhere in this report.

Compositionnot shipped

CycloneDX 1.5 output for installer-class artifacts is designed, not shipped. Component discovery works today; the signed SBOM document does not exist yet.

44 components identified, 41 with a resolved licence, 3 unresolved. The executables below install alongside the parent product and are governed software in their own right: an approval of the parent does not cover them.

componentversionpublisherlicencerole
dockerd.exe27.5.1Docker Inc.Apache-2.0Service, container daemon
containerd.exe1.7.25The Linux FoundationApache-2.0Service, container runtime
com.docker.build.exe4.38.0Docker Inc.LicenseRef-Docker-SubscriptionLong-lived process, build service
kubectl.exe1.32.1The Linux FoundationApache-2.0CLI, Kubernetes client
docker.exe27.5.1Docker Inc.Apache-2.0CLI, primary client
vpnkit.exe0.10.0Docker Inc.Apache-2.0Network proxy
Electron runtime32.2.7OpenJS FoundationMITEmbedded UI runtime
Forensics2What it touches, and when

Indicators and behaviournot shipped

ATT&CK technique mapping and D3FEND pairing are designed here at a depth the current pipeline does not reach. Observable extraction is real; the mapping from observable to technique is partly manual today.

Observables

typevaluecontext
Domainhub.docker.comRegistry endpoint in configuration defaults
Domaindesktop.docker.comUpdate channel in configuration defaults
Named pipe\\.\pipe\dockerDesktopEngineLocal control channel
Local socket127.0.0.1:2375Engine API, disabled by default
Service namecom.docker.serviceInstalled privileged helper

Techniques

techniquewhy it is listedcountermeasure
T1543.003Create or Modify System Process: Windows ServiceInstalls a privileged helper service. Expected for this product class and listed so the capability is recorded, not because it indicates compromise.Service binary verification and change detection
T1059.003Command and Scripting Interpreter: Windows Command ShellInstaller invokes shell commands during setup. Present in the NSIS script.Process spawn analysis
T1136Create AccountCreates a local group governing engine access.Local account monitoring

Technique presence describes capability, not intent. Every entry here is expected behaviour for an installer of this class, and none contributed to the verdict.

Timelinenot shipped

Reconstructed from artifact timestamps and analysis events. Ordering across sources is best-effort, clock skew between a build host and an analysis host is not resolved.

wheneventfromconfidence
2026-01-28T14:02:11ZArtifact compiledPE compile timestamp
2026-01-28T14:19:44ZArtifact signed and timestampedRFC 3161 countersignature
2026-06-14T00:00:00ZPrior version analysed in this tenantSimilarity history
2026-08-03T09:41:22ZSubmitted by endpoint agentAgent CON-WKS-4471
2026-08-03T09:43:07ZAnalysis completedAnalysis record

Confidence is struck as fineness, the same unit the register uses. Verified means the timestamp is signed or recorded by us; estimated means it is asserted by the artifact and unverifiable.

More of this

New posts on what a file tells you before you run it: headers, signatures, manifests, overlays, the fields most inventory never reads. Only when there is something worth the write-up.

We intend to offer a tool that does this across every file on an endpoint. You get one message when you can use it.

One field, any address. Those two things and nothing else, and replying to any of it removes you.