Cloud audit logs

Cloud investigations depend on logs that somebody had to switch on, keep, and put somewhere the attacker cannot reach.

None of those are automatic. Default retention is frequently short, some log types are off unless enabled, and if they are stored in the same account that was compromised, they can be deleted. This is discovered during the first serious incident, at which point the period you need is gone.

Checked against the primary source.

More on Cloud security