Example report
Docker Desktop Installer.exe
| allow | 87/ 100 | B88 / 100 | verified |
| verdict | file trust | vendor risk | attribution |
|---|---|---|---|
| confidence high, risk low | 5 weighted factors | identity verified | content-derived |
Verdict
Signed by a verified publisher, matching the declared product and version. No malicious signals in any content path that was examined. Two items below need a policy decision rather than a security one.
Key findings
- Authenticode signature valid and chains to a publicly trusted root. Subject matches the vendor identified from artifact content, not from the filename or the declared product string.
- Installs four additional executables that run as services or long-lived processes. Each is inventoried separately in Composition; they are the components that appear in an endpoint register with no catalog entry of their own.
- Requests elevation and installs machine-wide. This is expected for this product and is stated here because the approval decision depends on it.
- Bundles a Kubernetes distribution and a container runtime. Both are governed software in their own right and are not covered by an approval of the parent product.
Recommended actions
- Before approvalDecide whether the bundled container runtime and Kubernetes distribution are separately approved, or covered by this approval. They are listed individually in Composition.
- Before approvalConfirm the licence position. Docker Desktop requires a paid subscription above a company size and headcount threshold: this is a commercial obligation, not a technical one.
- On deploymentAdd the four bundled executables to the sanctioned register so they do not surface as unattributed binaries in endpoint inventory.
- OngoingThis product self-updates. Re-analysis on version change is the only way the approval stays accurate.
Decision4Why it concluded that, and whether to approve
Verdict factors
| factor | reading | weight | detail |
|---|---|---|---|
| Code signature | positive | high | Valid Authenticode chain, countersigned timestamp, subject corroborated against certificate transparency and company registration. |
| Malicious signals | positive | high | No rule matches in any examined content path. See Analysis coverage for what was and was not examined. |
| Vendor reputation | positive | medium | Identity verified against two independent registries plus certificate transparency. No single feed drove this. |
| Software category | neutral | medium | Developer tooling with container runtime capability. Elevated baseline risk by category, not by finding. |
| Licence obligations | attention | medium | Commercial subscription threshold applies. A policy question, not a security one. |
| Terms-of-service posture | neutral | low | Standard commercial terms. Telemetry is on by default and configurable. |
Scores
87/ 100 file trust
| dimension | weight | score | note |
|---|---|---|---|
| Malicious signals | 40% | 100 | No matches in examined paths |
| Code signing | 20% | 100 | Valid chain, timestamped |
| Vendor reputation | 20% | 92 | Verified identity, mature publisher |
| Software category | 15% | 45 | Container runtime, elevated baseline |
| Terms-of-service posture | 5% | 70 | Telemetry default-on |
Vendor2Who published this, and what corroborates it
Vendor intelligence
B88 / 100 vendor risk · identity verified · evidence completeness 92%
Identity confidence is graded, not asserted. Every line below is tied to something in the artifact itself: a certificate subject, a declared product string, because a package name is not a vendor.
| dimension | weight | score | note |
|---|---|---|---|
| Identity verification | 25% | 100 | Registration and certificate subject agree |
| Security posture | 25% | 78 | Published advisory process; no unresolved disclosures found |
| Code signing | 15% | 100 | Consistent signing across releases examined |
| Licence compliance | 15% | 80 | Clear terms; commercial threshold applies |
| Community health | 10% | 95 | Active public repositories, frequent releases |
| Vendor maturity | 10% | 90 | Established, funded, long operating history |
Evidence
| source | tied to | says |
|---|---|---|
| Certificate subject | The signature on this artifact | Docker Inc., US |
| Company registration | Subject name and jurisdiction from the certificate | Active registration matching the certificate subject |
| Certificate transparency | Domains in the certificate subject | Long-lived issuance history, no anomalies |
| Public repositories | Product name declared in the artifact version resource | Maintained, releases align with the declared version |
Enterprise readiness
| Deployment method | Machine-wide installer, elevation required |
|---|---|
| Silent install | Supported |
| Update mechanism | Self-updating, in-product |
| Uninstall | Registers an uninstall entry |
| Runs as service | Yes, four components |
| Network listeners | Local sockets and a named pipe |
| Telemetry | On by default, configurable |
| Offline operation | Partial, image pulls require network |
Approval readiness
Approve with conditions
Conditions
- Bundled components approved separately or explicitly covered
- Licence threshold confirmed against current headcount
- Re-analysis on version change
Rules matched
| Signed by verified publisher | allow |
|---|---|
| Minimum trust score ≥ 70 | allow |
| Category: container runtime | review |
| Commercial licence threshold | review |
Compliance3Framework posture, obligations, and the limits
Compliance
| framework | met | gap | review |
|---|---|---|---|
| NIST SP 800-53 | 6 | 0 | 2 |
| SOC 2 | 4 | 0 | 1 |
| ISO 27001:2022 A.8 | 5 | 0 | 1 |
| CMMC 2.0 | 3 | 0 | 1 |
| PCI-DSS v4.0 | 2 | 0 | 1 |
| HIPAA Security Rule | 2 | 0 | 0 |
| GDPR | 1 | 0 | 1 |
Controls
| control | status | note |
|---|---|---|
| CM-7Least functionalityNIST SP 800-53 | review | Bundled runtime expands installed functionality beyond the approved product |
| CM-11User-installed softwareNIST SP 800-53 | met | Machine-wide install; governed by policy |
| SI-7Software integrityNIST SP 800-53 | met | Signature verified, chain intact |
| SA-12Supply chain protectionNIST SP 800-53 | review | Four bundled components require their own provenance record |
| CC6.8Unauthorised softwareSOC 2 | met | Approval decision recorded with evidence |
| CC7.1Change detectionSOC 2 | review | Self-updating product; detection depends on re-analysis |
| A.8.19Software on operational systemsISO 27001:2022 A.8 | met | Install path and method recorded |
| A.8.30Outsourced developmentISO 27001:2022 A.8 | review | Bundled third-party components present |
Licence obligations
Commercial, with a free tier bounded by company size
| obligation | applies | note |
|---|---|---|
| Commercial-use restriction | yes | Paid subscription required above the vendor’s stated company size and revenue threshold |
| Attribution | yes | Third-party notices bundled with the product |
| Copyleft | no | No copyleft obligation on the parent artifact |
| Source disclosure | no | Not triggered by use as distributed |
| Patent grant | yes | Apache-2.0 components carry an express grant |
Analysis coverage
What was examined, and what was not. The limits belong next to the decision, not behind it.
Examined
| PE structure, sections, imports, resources | full |
|---|---|
| Authenticode signature and certificate chain | full |
| NSIS installer script and embedded payload listing | full |
| Bundled executables, headers, signatures, identity | full |
| Rule matching across extracted content | full |
Not examined
| Runtime behaviour | Static analysis only. Nothing here describes what the installer does when executed. |
|---|---|
| Container images pulled after installation | Fetched at runtime from a registry. Not present in the artifact and not analysed. |
| Multi-engine antivirus verdicts | Multi-engine antivirus runs on a customer-supplied key by design: the quota and the data-sharing decision stay with you rather than with us. No key is attached to this example, so no engines were consulted. |
| Advisory and vulnerability status | Not assessed. This report describes what the file is and who made it, not what is known to be wrong with the software. |
| Anything requiring the installer to be executed | No sandbox detonation was performed. Every statement in this report is derived from the artifact as it sits on disk. |
Composition4What it is made of, and what identifies it
File overview
| Type | PE32+ executable (GUI) x86-64, NSIS installer |
|---|---|
| Family | Windows installer |
| Size | 618.4 MB |
| Submitted | 2026-08-03T09:41:22Z |
| Completed | 2026-08-03T09:43:07Z |
File identifiers
| SHA-256 | e3b4c1a97f28d6054b0f39aa71c8d25e6f4a0b93cc7e18d2fa5b60947e3c1d88 |
|---|---|
| SHA-1 | 5f2a9c73e18b40d6ca27f9b3081de54a6c9f2b17 |
| MD5 | a94f3c7d21b58e0946f7c3d81ab52e6f |
| TLSH | T1F4A6B29C3E8047D5A1C6F03B95E2D871A4C0F63B8D95E2A07C4F1B36D8E5A092C7B04F |
Names
| Submitted as | Docker Desktop Installer.exe |
|---|---|
| Original filename | Docker Desktop Installer.exe |
| Product name | Docker Desktop |
| Internal name | Docker Desktop Installer |
Nearest in your own history
| artifact | tlsh distance | seen |
|---|---|---|
| Docker Desktop Installer.exe 4.37.2 | 41 | 2026-06-14 |
| Docker Desktop Installer.exe 4.36.0 | 63 | 2026-04-02 |
Technical details
| Machine | x86-64 |
|---|---|
| Subsystem | Windows GUI |
| Compile timestamp | 2026-01-28T14:02:11Z |
| Sections | 6 |
| Entry point section | .text |
| Overlay | Present, 612.8 MB NSIS payload |
| Base relocations | Present |
| ASLR / DEP / CFG | Enabled / Enabled / Enabled |
Sections
| name | characteristics | entropy | note |
|---|---|---|---|
| .text | CNT_CODE, MEM_EXECUTE, MEM_READ | 6.41 | Ordinary compiled code |
| .rdata | CNT_INITIALIZED_DATA, MEM_READ | 5.02 | |
| .data | CNT_INITIALIZED_DATA, MEM_READ, MEM_WRITE | 3.88 | |
| .rsrc | CNT_INITIALIZED_DATA, MEM_READ | 4.17 | Version resource, icons, manifest |
| .reloc | CNT_INITIALIZED_DATA, MEM_DISCARDABLE, MEM_READ | 5.64 | |
| .ndata | CNT_UNINITIALIZED_DATA, MEM_READ, MEM_WRITE | 0.00 | NSIS working section, zero raw size, allocated at load |
Imports
| module | functions | note |
|---|---|---|
| KERNEL32.dll | 84 | |
| USER32.dll | 31 | |
| ADVAPI32.dll | 19 | Service and registry APIs, consistent with an installer |
| SHELL32.dll | 12 | |
| ole32.dll | 7 | |
| COMCTL32.dll | 5 |
Signature
| Status | Valid |
|---|---|
| Subject | Docker Inc. |
| Issuer | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Digest algorithm | SHA-256 |
| Countersignature | RFC 3161 timestamp, 2026-01-28T14:19:44Z |
| Chain | Terminates in a publicly trusted root |
Enrichment
| source | consulted | result |
|---|---|---|
| Certificate transparency | yes | Issuance history consistent with a long-lived publisher |
| Company registration | yes | Active registration matching certificate subject |
| Verified vendor facts | yes | Founded, headquarters and parent company corroborated |
| Public repository health | yes | Active, releases align with declared version |
| Known-malware hash intelligence | yes | No record for this hashAbsence of a record is not evidence of safety and does not contribute to the verdict. |
| Community threat-intelligence pulses | yes | No pulses reference this artifactNever sufficient on its own: a single uncorroborated feed does not drive a verdict in either direction. |
| Licence resolution | yes | Component licences resolved for 41 of 44 bundled components |
| Multi-engine antivirus | no | Not consultedMulti-engine antivirus runs on your own vendor key by design: your quota, your data-sharing terms, not ours. That is a deliberate product decision rather than a limitation. No key is attached to this example, so no engines were consulted and no engine result appears anywhere in this report. |
Compositionnot shipped
CycloneDX 1.5 output for installer-class artifacts is designed, not shipped. Component discovery works today; the signed SBOM document does not exist yet.
44 components identified, 41 with a resolved licence, 3 unresolved. The executables below install alongside the parent product and are governed software in their own right: an approval of the parent does not cover them.
| component | version | publisher | licence | role |
|---|---|---|---|---|
| dockerd.exe | 27.5.1 | Docker Inc. | Apache-2.0 | Service, container daemon |
| containerd.exe | 1.7.25 | The Linux Foundation | Apache-2.0 | Service, container runtime |
| com.docker.build.exe | 4.38.0 | Docker Inc. | LicenseRef-Docker-Subscription | Long-lived process, build service |
| kubectl.exe | 1.32.1 | The Linux Foundation | Apache-2.0 | CLI, Kubernetes client |
| docker.exe | 27.5.1 | Docker Inc. | Apache-2.0 | CLI, primary client |
| vpnkit.exe | 0.10.0 | Docker Inc. | Apache-2.0 | Network proxy |
| Electron runtime | 32.2.7 | OpenJS Foundation | MIT | Embedded UI runtime |
Forensics2What it touches, and when
Indicators and behaviournot shipped
ATT&CK technique mapping and D3FEND pairing are designed here at a depth the current pipeline does not reach. Observable extraction is real; the mapping from observable to technique is partly manual today.
Observables
| type | value | context |
|---|---|---|
| Domain | hub.docker.com | Registry endpoint in configuration defaults |
| Domain | desktop.docker.com | Update channel in configuration defaults |
| Named pipe | \\.\pipe\dockerDesktopEngine | Local control channel |
| Local socket | 127.0.0.1:2375 | Engine API, disabled by default |
| Service name | com.docker.service | Installed privileged helper |
Techniques
| technique | why it is listed | countermeasure |
|---|---|---|
| T1543.003Create or Modify System Process: Windows Service | Installs a privileged helper service. Expected for this product class and listed so the capability is recorded, not because it indicates compromise. | Service binary verification and change detection |
| T1059.003Command and Scripting Interpreter: Windows Command Shell | Installer invokes shell commands during setup. Present in the NSIS script. | Process spawn analysis |
| T1136Create Account | Creates a local group governing engine access. | Local account monitoring |
Timelinenot shipped
Reconstructed from artifact timestamps and analysis events. Ordering across sources is best-effort, clock skew between a build host and an analysis host is not resolved.
| when | event | from | confidence |
|---|---|---|---|
| 2026-01-28T14:02:11Z | Artifact compiled | PE compile timestamp | |
| 2026-01-28T14:19:44Z | Artifact signed and timestamped | RFC 3161 countersignature | |
| 2026-06-14T00:00:00Z | Prior version analysed in this tenant | Similarity history | |
| 2026-08-03T09:41:22Z | Submitted by endpoint agent | Agent CON-WKS-4471 | |
| 2026-08-03T09:43:07Z | Analysis completed | Analysis record |
More of this
New posts on what a file tells you before you run it: headers, signatures, manifests, overlays, the fields most inventory never reads. Only when there is something worth the write-up.
We intend to offer a tool that does this across every file on an endpoint. You get one message when you can use it.