Evidence you do not control.
WHY IT DIFFERS
The systems are not yours and you cannot preserve them directly.
WHAT TO ESTABLISH
What the provider retains For how long How to request it What process is required
WHY IN ADVANCE
Requests during an incident are slow and the retention period may pass.
WHAT TO DO IMMEDIATELY ON AN INCIDENT
Contact the provider and request preservation.
WHY
It stops the retention clock on relevant records.
WHAT TO REQUEST
Logs for the relevant period Authentication records Administrative actions Any snapshots or backups from before the incident
WHY EARLIER BACKUPS
They may show the system before compromise.
WHAT TO PRESERVE YOURSELF
Anything you can export Configuration as it currently stands Your own records of access
WHAT TO ESTABLISH
Whether the provider will assist, and what they require.
WHAT MANY REQUIRE
Formal requests Verification of authority Sometimes legal process
WHAT TO ESTABLISH ABOUT SHARED INFRASTRUCTURE
That your investigation does not affect others.
WHY
Shared systems host other customers.
WHAT TO AVOID
Testing or examining infrastructure that is not yours.
WHAT TO ESTABLISH ABOUT SNAPSHOTS
Taking one before changing anything.
WHY
It preserves the state, and it is usually simple.
WHAT TO RECORD
What was taken, when, and its identifier.
WHAT TO ESTABLISH ABOUT DELETION
That evidence is not deleted by automatic processes during the investigation.
WHAT TO DO
Suspend lifecycle rules that would remove it.