As more organizations move to the cloud, the need to perform digital forensics and incident response in such environments is becoming more prevalent. It can be a challenge to keep track of the differences between the cloud providers and how to respond in their respective environments.
The new Enterprise Cloud Forensics & Incident Response poster provides guidance on terminology and log sources across the major cloud providers (AWS, Google, and Microsoft), along with a CLI cheat sheet for gathering evidence from each cloud.
In this livestream, FOR509: Enterprise Cloud Forensics & Incident Response (www.sans.org/FOR509) course co-author Megan Roddie as she explains how you can maximize this free resource debuting at the DFIR Summit 2022 (www.sans.org/dfirsummit)