Forensic Chapter 7 - Cloud Forensic
1. Two Cloud Forensic Ways
Computer forensic in the cloud
- Take a snapshot from VMs
- Prepare a VM as forensics workstation
- Attach your VM snapshot as read-only
- Do computer forensic
Forensic in cloud environment
- Establish assets inventory
- Deploy and integrate SIEM (Security information and Event Management)
- Keep logging and send logs to SIEM
- Define and apply secure environment for logging and SIEM infrastructure
- Setup preset credentials to access your VMs in the cloud
- Build-up skills and capabilities
- Continuous improvement
2. SIEM Stack
Paid Version
Splunk
expensive cloud forensic platformFree Version
Elastic
free colud forensic platform- Diagram
- Architecture