Leanpub Header

Skip to main content

Forensics in the Cloud

Reconstructing Attacks Across AWS, Azure, GCP, and Oracle Cloud

Forensics in the Cloud
This book is 100% completeLast updated on 2026-09-06

When an attack hits the cloud, the evidence can disappear fast. Forensics in the Cloud shows defenders how to find, preserve and piece together the clues across AWS, Azure, GCP and Oracle Cloud. With practical workflows, code and real-world scenarios, it’s a hands-on guide to uncovering what happened and proving it.

Minimum price

$29.00

$39.00

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

PDF
EPUB
WEB
APP
209
Pages
About

About

About the Book

Cloud forensics demands different skills than traditional digital forensics. Public clouds generate rich, structured logs across dozens of services, yet attackers can compromise, tamper with, or destroy that evidence faster than responders can collect it. This book teaches you how to investigate security incidents across AWS, Microsoft Azure, Google Cloud Platform, and Oracle Cloud Infrastructure by showing you where evidence lives, how long it persists, how to collect it without destroying integrity, and how to reconstruct attacker activity from logs, snapshots, and configuration changes. You will find production-quality code examples, provider-specific investigation workflows, real-world incident walkthroughs using synthetic data, and practical guidance on maintaining chain-of-custody in environments you do not fully control. This is a hands-on reference for defenders who need to understand what happened in their cloud, who did it, and how to prove it.

Author

About the Author

Steve Publications

Steve is a technology professional with more than 20 years of experience in software development, server infrastructure, cybersecurity, vulnerability research and reverse engineering. Throughout his career, he has designed, secured, analyzed and tested complex software and infrastructure, with a particular focus on understanding how systems fail and how they can be made more secure.

Outside of work, Steve enjoys sharing knowledge with the technology community. He collaborates with researchers, industry experts and technology professionals to write practical books covering software development, cybersecurity, cloud computing, networking, DevOps, artificial intelligence and enterprise technologies. His books focus on practical learning through clear explanations, real-world examples and hands-on exercises. With more than two decades of industry experience, his goal is to help IT professionals, students and technology enthusiasts build useful skills and stay current in a rapidly changing industry.

We believe readers deserve to know how our books are created. Most of our authors are not native English speakers, so we use AI to help translate, proofread manuscripts, fix grammar, improve sentence structure and make technical explanations easier to read. AI is used as an editing tool only. It does not replace the research, technical knowledge or hands-on experience behind our books. Some of our authors also prefer to remain anonymous for privacy or professional reasons. In those cases, we publish their work under a different name. The author's name may be different, but the quality of the content and our review process remain the same.

Every book is written, reviewed and maintained by experienced technology professionals, with contributions from our private technical community of more than 420 engineers and researchers. We spend far more time validating technical accuracy and keeping our content up to date than generating text. We are always interested in working with experienced professionals who have deep expertise in a particular technology or domain. If you would like to publish a book with us or help review an existing manuscript, we'd love to hear from you. Send us a message describing your area of expertise. We are especially interested in niche technologies, specialized skills and emerging topics that are underrepresented in existing technical literature.

If you look through the contents of our books, you'll see practical examples, detailed explanations and material that is regularly updated. Our goal is to publish books that professionals can actually rely on, not low-effort AI-generated content. If you ever feel that one of our books does not meet that standard, Leanpub offers a 60-day money-back guarantee. Feel free to request a refund if you are not satisfied with your purchase.

Contents

Table of Contents

Reconstructing Attacks Across AWS, Azure, GCP, and Oracle Cloud

Introduction: The New Crime Scene

  1. The 3:00 AM Alert: A Realistic Cloud Incident
  2. Why Cloud Forensics Is Not Just Server Forensics in a Data Center
  3. What You Will Learn and How to Use This Book
  4. A Note on Scope, Ethics, and the Defensive Posture

Chapter 1: Foundations of Cloud Forensics

  1. The Shared Responsibility Model as a Forensic Boundary
  2. Ephemeral Infrastructure and the Race Against Time
  3. Cloud Forensic Artifacts: Classification and Priority
  4. Legal, Compliance, and Chain-of-Custody Considerations
  5. The Three Laws of Cloud Evidence Collection

Chapter 2: Cloud Architecture and Forensic Visibility

  1. Public Cloud Tenancy Models and What You Can See
  2. Compute, Network, Storage, and Database Layers: Visibility Spectrum
  3. Managed Services and the Forensic Black Box Problem
  4. Architecting for Forensics: Logging, Monitoring, and Evidence Preservation by Design
  5. Regional Boundaries, Cross-Account Access, and Evidence Scoping

Chapter 3: Identity and Access Management as the Forensic Center

  1. IAM Fundamentals: Users, Roles, Groups, and Policies
  2. Mapping Identity Across AWS IAM, Azure AD/Entra ID, GCP IAM, and OCI IAM
  3. Authentication Events: Sign-Ins, MFA, and Anomalous Patterns
  4. Authorization Decisions: Why Did This User or Service Have Access?
  5. Cross-Account, Cross-Tenant, and Federated Identity Forensics
  6. Code Example: Parsing and Analyzing IAM Activity Logs

Chapter 4: Cloud Audit and Activity Logs

  1. AWS CloudTrail: Logs, Insights, and Data Events
  2. Azure Activity Logs and Diagnostic Settings
  3. Google Cloud Audit Logs and Organization Policy
  4. OCI Audit Service and Events
  5. Cross-Provider Comparison: What Each Logs and What It Misses
  6. Code Example: Building a Unified Audit Log Search Tool

Chapter 5: Authentication and Sign-In Forensics

  1. Sign-In Events: What to Look for in Authentication Logs
  2. Impossible Travel, Geolocation Anomalies, and Velocity Analysis
  3. Token Theft, Session Hijacking, and Replay Attacks
  4. Key-Based Authentication and Access Key Forensics
  5. MFA Bypass, Prompt Fatigue, and Consent Attacks
  6. Code Example: Detecting Suspicious Sign-In Patterns Across Providers

Chapter 6: Compute Instance Forensics

  1. Instance Metadata and the Initial Reconnaissance Trail
  2. Snapshot Forensics: Capturing Disks Before and During Incidents
  3. Memory Acquisition in the Cloud: Tools, Timing, and Limitations
  4. Process and Command-Line Artifacts
  5. Instance Creation and Configuration as Evidence
  6. Code Example: Automated Instance Evidence Collection Script

Chapter 7: Container and Kubernetes Forensics

  1. Container Lifecycle and Forensic Implications
  2. Image Layer Forensics and Registry Investigation
  3. Runtime Forensics: Processes, Networks, and Volumes in Containers
  4. Kubernetes API Server Logs and Audit Trail
  5. EKS, AKS, GKE, and OKE: Managed Kubernetes Forensic Differences
  6. Code Example: Container and Kubernetes Forensic Analysis Tool

Chapter 8: Serverless Forensics

  1. Serverless Architecture and Where Evidence Lives
  2. AWS Lambda Forensics: Execution Logs and Invocation Patterns
  3. Azure Functions and GCP Cloud Functions Investigation
  4. Code Injection and Function Misconfiguration as Attack Vectors
  5. Timing Attacks, Trigger Manipulation, and Cold-Start Forensics
  6. Code Example: Serverless Function Log Analysis Pipeline

Chapter 9: Network Forensics and Telemetry

  1. Cloud Network Models: VPC, VNet, VPC, and Virtual Cloud Network
  2. Flow Logs: AWS VPC Flow Logs, Azure NSG Flow Logs, GCP Flow Logs, OCI Flow Logs
  3. DNS Query Logs and Resolution Forensics
  4. Load Balancer, CDN, and Gateway Logs
  5. Network-Level Indicators: Port Scanning, Beaconing, and Data Egress
  6. Code Example: Network Flow Log Analysis and Visualization

Chapter 10: Storage and Data Access Forensics

  1. Object Storage Forensics: S3, Blob Storage, Cloud Storage, and Object Storage
  2. Access Patterns, Policy Changes, and Public Exposure Events
  3. Database Forensics: RDS, Azure SQL, Cloud SQL, and Autonomous Database
  4. Key Management Service Forensics: KMS, Azure Key Vault, Cloud KMS, OCI Vault
  5. Detecting Data Exfiltration: Volume, Timing, and Destination Analysis
  6. Code Example: Storage Access Log Analysis for Data Loss Indicators

Chapter 11: Configuration Change and Infrastructure Forensics

  1. Infrastructure as Code and Change Management as Evidence
  2. Security Group, Network Security List, and Firewall Rule Modifications
  3. New IAM Roles, Users, and Permission Escalation Events
  4. Unusual Resource Creation: Instances, Buckets, and Functions
  5. Detecting and Tracking Configuration Drift
  6. Code Example: Infrastructure Change Detection and Alerting

Chapter 12: Persistence and Defense Evasion in the Cloud

  1. Cloud-Specific Persistence Mechanisms
  2. Log Tampering, Deletion, and Suppression
  3. Cloud API Proxying and C2 Infrastructure
  4. Compromised CI/CD Pipelines and Supply Chain Attacks
  5. Resource Misuse: Cryptominers, Botnets, and Spam Infrastructure
  6. Code Example: Persistence and Defense Evasion Detection Script

Chapter 13: Compromised Credentials and Privilege Escalation

  1. Credential Acquisition: Phishing, Key Exposure, and Metadata Service Abuse
  2. Analyzing Compromised Access Key Usage Patterns
  3. Role Assumption and Privilege Escalation Paths
  4. Policy Misconfigurations That Enable Escalation
  5. Containment Strategies and Impact Assessment
  6. Code Example: Credential Abuse and Privilege Escalation Analysis

Chapter 14: Incident Scenarios: Walkthrough Investigations

  1. Scenario 1: Compromised Developer Credentials on AWS
  2. Scenario 2: Lateral Movement via Azure Role Elevation
  3. Scenario 3: Data Exfiltration from GCP Cloud Storage
  4. Scenario 4: Multi-Cloud Persistence and Command-and-Control
  5. Scenario 5: Supply Chain Attack via CI/CD Pipeline Compromise

Chapter 15: Evidence Preservation and Chain of Custody

  1. Preservation Principles: Integrity, Authenticity, and Reproducibility
  2. Snapshotting, Exporting, and Archiving Evidence
  3. Hashing and Verification in Cloud Environments
  4. Chain of Custody: Documentation, Access Controls, and Legal Requirements
  5. Working with Providers: Preservation Requests and Legal Holds
  6. Code Example: Evidence Preservation and Verification Toolkit

Chapter 16: Multi-Cloud and Cross-Provider Forensics

  1. Multi-Cloud Architecture and Attack Surface Considerations
  2. Unified Log Aggregation and Cross-Provider Correlation
  3. Federated Identity and Cross-Cloud Access Patterns
  4. Data Replication, Synchronization, and Evidence Fragmentation
  5. Building a Multi-Cloud Investigation Playbook
  6. Code Example: Multi-Cloud Log Correlation Engine

Chapter 17: Automation, Tooling, and Building a Cloud Forensics Platform

  1. Forensics Automation Philosophy: When to Automate and What to Trust
  2. Building a Centralized Log Lake for Forensic Investigations
  3. SIEM Integration: Splunk, Sentinel, Chronicle, and Open-Source Alternatives
  4. Scripting Evidence Collection: Python, Bash, and Provider CLIs
  5. Building Custom Detection Rules and Alerting Pipelines
  6. Code Example: Complete Cloud Forensics Automation Framework

Chapter 18: Advanced Topics and Future Directions

  1. Confidential Computing and Forensic Limitations
  2. AI and Machine Learning in Cloud Incident Investigation
  3. Adversarial Adaptation: Attackers Evolving Around Cloud Defenses
  4. Regulatory Changes, Cross-Border Evidence, and Compliance
  5. Where Cloud Forensics Is Headed: Trends and Recommendations

Conclusion: Preparing for the Next Incident

  1. The Forensic Readiness Checklist
  2. Building Organizational Muscle Memory
  3. Key Takeaways and Recommended Next Steps

References

Get the free sample chapters

Click the buttons to get the free sample in PDF or EPUB, or read the sample online here

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub