Cloud forensics depends on provider evidence
In a cloud incident you can only investigate what the provider records and lets you retrieve.
There is no disk to image unless you arranged for one, and no visibility below your own layer. What logs exist, how far back they go and how quickly you can get them are determined by choices made long before, and by the provider's own limits. Several of those choices are off by default.
More on Digital forensics
- Forensic copies protect original evidenceMark the copy, never the original
- Hashes can show evidence stayed unchangedThe same short string, twice
- Timestamps need interpretationOne moment, three different times
- Memory can reveal what disk cannotIt has to unwrap itself to run
- Forensic tooling can change the thing examinedYou leave prints of your own
- Deleted does not always mean goneThe card, not the book
