Cloud Forensics Methodology
Cloud Forensics Methodology
Cloud forensics requires adapted methodologies:
Evidence Sources in Cloud:
- API Audit Logs: All API calls and administrative actions
- Resource Configurations: Security groups, network ACLs, IAM policies
- Flow Logs: Network traffic metadata
- Object Storage Logs: Access to S3, Blob Storage, Cloud Storage
- Compute Snapshots: EBS snapshots, managed disk snapshots
- Memory Dumps: If supported by instance type
- Application Logs: CloudWatch, Azure Monitor, Stackdriver