AWS
Data Collection with Storage
External block storage basically acts as a Cloud USB drive allowing the addition of storage to the cloud system.
If you provision more block storage, it will appear automatically in Windows
In Linux we can create a mount point
Collection of AWS Storage
Cloud Logging
When in possession of Cloud logs, manual analysis is extremely difficult, use automated tools
Examine the logs in a web server like view
Revoking Cloud Keys
Most compromises have to do with an unauthorized user gaining access to a cloud key
AWS IAM search by username or Key ID by clicking IAM --> Users
For Azure AD make sure to reset the password twice!!!
Last updated