Terminology Index

Glossary

1801 terms

Open concept maps

Showing 289-320 of 1801 terms

C
32

Cloud IR Evidence Sources

The places a cloud responder gathers evidence during an incident, control-plane and audit logs, identity sign-in logs, network flow logs, disk snapshots, memory captures, and provider detection findings. Knowing them is essential to investigate effectively.

Cloud investigations draw on a defined set of sources, each revealing a different facet: audit logs show who did what via the API, identity logs show authentication, flow logs show network movement, and snapshots and memory show workload state. Because some of these are off by default or short-lived, ensuring they are enabled and preserved in advance is a prerequisite for being able to investigate at all.

Introduced in: Cloud Incident Response

Examples

  • Pulling control-plane logs to see an attacker's API actions.
  • Using identity sign-in logs to confirm a compromised account.
  • Taking a disk snapshot as workload-level evidence.

No related terms linked yet.