DFIR Investigations – Logs in Azure
In the previous chapter, we discussed responding to incidents in Amazon Web Services (AWS). This chapter will focus on responding to incidents in Microsoft Azure, the second most popular cloud computing product. One critical aspect of incident response in Azure is analyzing log data from different Azure services. In this chapter, we will explore the various log sources available in Azure, how to acquire them, and best practices for analyzing this data to detect, contain, and resolve security incidents in Azure. By understanding the tools and techniques available for incident response in Azure, incident response professionals can better protect and respond to an organization’s cloud infrastructure in the context of a security incident.
Following a similar pattern to AWS, understanding which logs within Azure are available by default versus what defenders and investigators may have to enable is critical to cloud forensics. This chapter...