digitc1 / AzLandingZone

Pipeline for the AZLandingZone module developed by DIGIT.C.1
Other
0 stars 0 forks source link

Forensic capture of Azure VMs #95

Open MiklosEC opened 2 years ago

MiklosEC commented 2 years ago

As a CSIRC analyst I want my Axiom Magnet workstation to be able to acquire the right credentials so that I can carry out a forensic capture of Azure VMs in the EC Azure IaaS/PaaS tenant.

Substories:

  1. As a CSIRC analyst, working on my Axiom Magnet workstation, I can assume the right S2 role in any tenant and subscription, so that the right credentials are applied to my session.
  2. Once the right credentials are applied, the CSIRC analyst, can access the target VM and capture the disk image.
  3. Once the right credentials are applied, the CSIRC analyst can access the target VM and capture the memory image.
  4. Once the right credentials are applied, the CSIRC analyst can access the target VM and create a full clone of the VM.
  5. Once the forensic image has been captured, the CSIRC analyst can can send the captured image to the Forensic image bucket in the CSIRC tenant. Architecture 01 Architecture 02
augustincolle-digit commented 2 years ago

Some requests for clarification on my side for the capture only:

I created a first proposal for the procedure, can you have a look and tell me if this fits: https://webgate.ec.europa.eu/fpfis/wikis/display/CVTF/CSIRC+incident+response