Cloud Log Preservation
Ensuring cloud logs needed for an investigation are captured, retained, and protected from deletion or tampering, including before an incident, since many cloud logs are off by default or expire quickly and cannot be recovered once gone.
Concept Neighborhood
Start here
Cloud Native vs Lifted
The most substantial related concept here, covered by 8 lessons.
AWS CloudTrail Investigation
Using AWS CloudTrail logs, which record API calls and account activity, to investigate a cloud incident: who did what, from where, and when. It is the primary evidence source for AWS control-plane actions.
6
lessons
Azure Incident Investigation
Investigating a security incident in Microsoft Azure using its logs and signals, such as Entra ID sign-in logs, activity logs, and Microsoft Defender alerts, to determine what an attacker did and how far they reached.
6
lessons
Cloud IR Evidence Sources
The places a cloud responder gathers evidence during an incident, control-plane and audit logs, identity sign-in logs, network flow logs, disk snapshots, memory captures, and provider detection findings. Knowing them is essential to investigate effectively.
6
lessons
Cloud IR Timeline Management
Building and maintaining an accurate chronological record of a cloud incident, ordering events from logs across identity, control plane, and workloads so responders understand what happened, in what sequence, and how far the attacker reached.
6
lessons
Related Lessons
6 lessons cover this conceptCloud IR Preparation and Decision-Making
Cloud Security Engineer
AWS Incident Investigation
Cloud Security Engineer
Azure Identity and Resource Investigation
Cloud Security Engineer
Evidence Collection, Integrity, and Custody
Cloud Security Engineer
Cloud-Specific Incident Playbooks
Cloud Security Engineer
Playbooks, Automation, and Measurement
Cloud Security Engineer
Sign in to open lesson content directly.
