Forensic Analysis of Cloud Virtual Environments

Art Sedighi, Doug Jacobson · 2019

This paper outlined a process via which forensic analysis can be done with the Microsoft Azure cloud environment. Cloud benefits from a number of characteristics such as agility and virtual environment which do not benefit the forensic process once an incident takes place. The forensic process, which includes Identification, Preservation, Acquisition, Examination and Reporting is analyzed in this paper vis-à-vis Azure's capability to investigate an incident once an alert of incident is generated. Azure has tooling and capability in place that aims to reduce the need for an investigative process, i.e. prevent an incident from taking place, but the same tools are then used to aide the investigative process as those tools present the line defense against a rouge attacker, and once subverted, traces left in those tools can be used for forensics analysis.

Read the paper · More papers on PaperTik