Forensic acquisition of GCP instances
Like the steps we saw for AWS and Microsoft Azure, forensic acquisition of a GCP compute follows the same steps. We will first take a snapshot of the compute engine instance and then attach the snapshot as a separate drive to another forensic collector compute instance so we can do a bit-by-bit copy before exporting the disk image via cloud storage or any other data transfer means.
Step 1 – creating a snapshot of the compute engine instance
So, let us look at the pre-requisite steps to acquire a forensic image of a compute instance:
- The first step is to create a disk snapshot of the compute engine instance; this can be done by accessing the navigation menu under Storage and selecting Snapshots. GCP offers two forms of snapshots. The first is regular snapshots, which include a complete disk snapshot of the compute engine instance, while the second is instant snapshots, which are more like an in-place backup of the disk used...