DFIR Investigations – Logs in GCP
You must have noticed each cloud service provider’s common resources and elements by now. In this chapter, we will dive straight into the security capabilities of Google Cloud Platform (GCP), what log sources are available, and how we can conduct our investigation. Note that cloud providers may use common terminologies. However, the applications and availability of logs may differ for each cloud service provider. Therefore, it is essential to understand which logs will be available during an incident investigation.
In Chapter 3, we briefly introduced specific cloud service offerings within GCP; in this chapter, we will dig deep into some of its core components and digital forensics. This chapter outlines the logs available for some of the critical GCP services and products discussed in Chapter 3 and looks at utilizing these sources in the context of an investigation.
Specifically, we will discuss the following topics in this chapter...