Glossary

    Cloud Forensics

    Incident Response

    Cloud Forensics is the process of collecting and analyzing evidence from cloud resources after a security incident. Unlike traditional forensics, cloud forensics works with API logs, metadata, and snapshots rather than physical hardware.

    AWS Evidence Sources

    • CloudTrail: who did what, when, from where (API calls)
    • VPC Flow Logs: network traffic metadata (source, destination, ports, bytes)
    • EBS snapshots: point-in-time disk images for offline analysis
    • Memory dumps: using SSM to capture running memory from EC2 instances
    • S3 access logs: who accessed which objects
    • GuardDuty findings: correlated threat intelligence

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.