Terminology Index
Glossary
1801 terms
Showing 289-320 of 1801 terms
Cloud IR Evidence Sources
The places a cloud responder gathers evidence during an incident, control-plane and audit logs, identity sign-in logs, network flow logs, disk snapshots, memory captures, and provider detection findings. Knowing them is essential to investigate effectively.
Cloud investigations draw on a defined set of sources, each revealing a different facet: audit logs show who did what via the API, identity logs show authentication, flow logs show network movement, and snapshots and memory show workload state. Because some of these are off by default or short-lived, ensuring they are enabled and preserved in advance is a prerequisite for being able to investigate at all.
Introduced in: Cloud Incident Response
Examples
- Pulling control-plane logs to see an attacker's API actions.
- Using identity sign-in logs to confirm a compromised account.
- Taking a disk snapshot as workload-level evidence.
No related terms linked yet.
