Reconstructing Attacks Across AWS, Azure, GCP, and Oracle Cloud
Introduction: The New Crime Scene
- The 3:00 AM Alert: A Realistic Cloud Incident
- Why Cloud Forensics Is Not Just Server Forensics in a Data Center
- What You Will Learn and How to Use This Book
- A Note on Scope, Ethics, and the Defensive Posture
Chapter 1: Foundations of Cloud Forensics
- The Shared Responsibility Model as a Forensic Boundary
- Ephemeral Infrastructure and the Race Against Time
- Cloud Forensic Artifacts: Classification and Priority
- Legal, Compliance, and Chain-of-Custody Considerations
- The Three Laws of Cloud Evidence Collection
Chapter 2: Cloud Architecture and Forensic Visibility
- Public Cloud Tenancy Models and What You Can See
- Compute, Network, Storage, and Database Layers: Visibility Spectrum
- Managed Services and the Forensic Black Box Problem
- Architecting for Forensics: Logging, Monitoring, and Evidence Preservation by Design
- Regional Boundaries, Cross-Account Access, and Evidence Scoping
Chapter 3: Identity and Access Management as the Forensic Center
- IAM Fundamentals: Users, Roles, Groups, and Policies
- Mapping Identity Across AWS IAM, Azure AD/Entra ID, GCP IAM, and OCI IAM
- Authentication Events: Sign-Ins, MFA, and Anomalous Patterns
- Authorization Decisions: Why Did This User or Service Have Access?
- Cross-Account, Cross-Tenant, and Federated Identity Forensics
- Code Example: Parsing and Analyzing IAM Activity Logs
Chapter 4: Cloud Audit and Activity Logs
- AWS CloudTrail: Logs, Insights, and Data Events
- Azure Activity Logs and Diagnostic Settings
- Google Cloud Audit Logs and Organization Policy
- OCI Audit Service and Events
- Cross-Provider Comparison: What Each Logs and What It Misses
- Code Example: Building a Unified Audit Log Search Tool
Chapter 5: Authentication and Sign-In Forensics
- Sign-In Events: What to Look for in Authentication Logs
- Impossible Travel, Geolocation Anomalies, and Velocity Analysis
- Token Theft, Session Hijacking, and Replay Attacks
- Key-Based Authentication and Access Key Forensics
- MFA Bypass, Prompt Fatigue, and Consent Attacks
- Code Example: Detecting Suspicious Sign-In Patterns Across Providers
Chapter 6: Compute Instance Forensics
- Instance Metadata and the Initial Reconnaissance Trail
- Snapshot Forensics: Capturing Disks Before and During Incidents
- Memory Acquisition in the Cloud: Tools, Timing, and Limitations
- Process and Command-Line Artifacts
- Instance Creation and Configuration as Evidence
- Code Example: Automated Instance Evidence Collection Script
Chapter 7: Container and Kubernetes Forensics
- Container Lifecycle and Forensic Implications
- Image Layer Forensics and Registry Investigation
- Runtime Forensics: Processes, Networks, and Volumes in Containers
- Kubernetes API Server Logs and Audit Trail
- EKS, AKS, GKE, and OKE: Managed Kubernetes Forensic Differences
- Code Example: Container and Kubernetes Forensic Analysis Tool
Chapter 8: Serverless Forensics
- Serverless Architecture and Where Evidence Lives
- AWS Lambda Forensics: Execution Logs and Invocation Patterns
- Azure Functions and GCP Cloud Functions Investigation
- Code Injection and Function Misconfiguration as Attack Vectors
- Timing Attacks, Trigger Manipulation, and Cold-Start Forensics
- Code Example: Serverless Function Log Analysis Pipeline
Chapter 9: Network Forensics and Telemetry
- Cloud Network Models: VPC, VNet, VPC, and Virtual Cloud Network
- Flow Logs: AWS VPC Flow Logs, Azure NSG Flow Logs, GCP Flow Logs, OCI Flow Logs
- DNS Query Logs and Resolution Forensics
- Load Balancer, CDN, and Gateway Logs
- Network-Level Indicators: Port Scanning, Beaconing, and Data Egress
- Code Example: Network Flow Log Analysis and Visualization
Chapter 10: Storage and Data Access Forensics
- Object Storage Forensics: S3, Blob Storage, Cloud Storage, and Object Storage
- Access Patterns, Policy Changes, and Public Exposure Events
- Database Forensics: RDS, Azure SQL, Cloud SQL, and Autonomous Database
- Key Management Service Forensics: KMS, Azure Key Vault, Cloud KMS, OCI Vault
- Detecting Data Exfiltration: Volume, Timing, and Destination Analysis
- Code Example: Storage Access Log Analysis for Data Loss Indicators
Chapter 11: Configuration Change and Infrastructure Forensics
- Infrastructure as Code and Change Management as Evidence
- Security Group, Network Security List, and Firewall Rule Modifications
- New IAM Roles, Users, and Permission Escalation Events
- Unusual Resource Creation: Instances, Buckets, and Functions
- Detecting and Tracking Configuration Drift
- Code Example: Infrastructure Change Detection and Alerting
Chapter 12: Persistence and Defense Evasion in the Cloud
- Cloud-Specific Persistence Mechanisms
- Log Tampering, Deletion, and Suppression
- Cloud API Proxying and C2 Infrastructure
- Compromised CI/CD Pipelines and Supply Chain Attacks
- Resource Misuse: Cryptominers, Botnets, and Spam Infrastructure
- Code Example: Persistence and Defense Evasion Detection Script
Chapter 13: Compromised Credentials and Privilege Escalation
- Credential Acquisition: Phishing, Key Exposure, and Metadata Service Abuse
- Analyzing Compromised Access Key Usage Patterns
- Role Assumption and Privilege Escalation Paths
- Policy Misconfigurations That Enable Escalation
- Containment Strategies and Impact Assessment
- Code Example: Credential Abuse and Privilege Escalation Analysis
Chapter 14: Incident Scenarios: Walkthrough Investigations
- Scenario 1: Compromised Developer Credentials on AWS
- Scenario 2: Lateral Movement via Azure Role Elevation
- Scenario 3: Data Exfiltration from GCP Cloud Storage
- Scenario 4: Multi-Cloud Persistence and Command-and-Control
- Scenario 5: Supply Chain Attack via CI/CD Pipeline Compromise
Chapter 15: Evidence Preservation and Chain of Custody
- Preservation Principles: Integrity, Authenticity, and Reproducibility
- Snapshotting, Exporting, and Archiving Evidence
- Hashing and Verification in Cloud Environments
- Chain of Custody: Documentation, Access Controls, and Legal Requirements
- Working with Providers: Preservation Requests and Legal Holds
- Code Example: Evidence Preservation and Verification Toolkit
Chapter 16: Multi-Cloud and Cross-Provider Forensics
- Multi-Cloud Architecture and Attack Surface Considerations
- Unified Log Aggregation and Cross-Provider Correlation
- Federated Identity and Cross-Cloud Access Patterns
- Data Replication, Synchronization, and Evidence Fragmentation
- Building a Multi-Cloud Investigation Playbook
- Code Example: Multi-Cloud Log Correlation Engine
Chapter 17: Automation, Tooling, and Building a Cloud Forensics Platform
- Forensics Automation Philosophy: When to Automate and What to Trust
- Building a Centralized Log Lake for Forensic Investigations
- SIEM Integration: Splunk, Sentinel, Chronicle, and Open-Source Alternatives
- Scripting Evidence Collection: Python, Bash, and Provider CLIs
- Building Custom Detection Rules and Alerting Pipelines
- Code Example: Complete Cloud Forensics Automation Framework
Chapter 18: Advanced Topics and Future Directions
- Confidential Computing and Forensic Limitations
- AI and Machine Learning in Cloud Incident Investigation
- Adversarial Adaptation: Attackers Evolving Around Cloud Defenses
- Regulatory Changes, Cross-Border Evidence, and Compliance
- Where Cloud Forensics Is Headed: Trends and Recommendations
Conclusion: Preparing for the Next Incident
- The Forensic Readiness Checklist
- Building Organizational Muscle Memory
- Key Takeaways and Recommended Next Steps