Forensic acquisition of Microsoft Azure Instances
Like AWS, Microsoft Azure offers a similar approach when collecting the full disk image of an Azure Virtual Machine (VM) instance. You will have to specifically create a snapshot and then look to export the snapshot. Let us look at these specific steps in detail.
Step 1 – creating an Azure VM Snapshot
As indicated earlier, each cloud platform will have slight variations in terms of the steps to achieve an entire disk and memory imaging; familiarity with these variations will help investigators greatly to the point where they can automate basic tasks if the number of VMs for forensic acquisition is significant:
- The first step is ensuring investigators have information about the infected Azure VM. This includes the VM name and operating system.
- Investigators can create a full disk snapshot of this infected Azure VM. Investigators may prefer to turn off the VM entirely before taking the snapshot. Snapshots are...