DFIR Evidence Collection and Preservation for the Cloud


Posted on in Presentations

One of the biggest challenges with cloud environments today is that evidence retention works on a continuous sliding time window. This means evidence is slowly aging out of existence, or evidence may never have been generated. This talk will take attendees through a review of what should be configured in; Azure, AWS, Google Cloud, Microsoft 365, or Google Workspace platforms.


Participants
Josh Lemon

Speaker

Director, Global MDR, Uptycs & SANS

Megan Roddie

Speaker

Author and Instructor in Development, SANS


Share With Your Community