Cloud Productivity Suites
By this point in the book, you are well acquainted with the core components and log sources that are integral to Cloud Service Providers (CSPs) such as Amazon Web Services (AWS), Azure, and Google Cloud Platform (GCP). As we pivot to productivity suites, it’s crucial to recognize that these platforms—namely Microsoft 365 and Google Workspace—are often the epicenter of organizational data and activity. The investigation of incidents in these environments comes with its own unique challenges and possibilities, as these services offer not just computing and storage but also extensive collaborative tools, all available through a Software as a Service (SaaS) model. The SaaS model, though convenient for organizations, means analysis will be dependent on which log sources are made available for investigators by the products.
It’s important to note that AWS does not have a cloud productivity suite akin to Microsoft 365 or Google Workspace...