Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Forensic capture of Azure VMs #95

Open
MiklosEC opened this issue Feb 6, 2022 · 1 comment
Open

Forensic capture of Azure VMs #95

MiklosEC opened this issue Feb 6, 2022 · 1 comment
Assignees
Labels
enhancement New feature or request question Further information is requested

Comments

@MiklosEC
Copy link

MiklosEC commented Feb 6, 2022

As a CSIRC analyst I want my Axiom Magnet workstation to be able to acquire the right credentials so that I can carry out a forensic capture of Azure VMs in the EC Azure IaaS/PaaS tenant.

  • Change it so that the story isn’t about acquiring the credentials but acquiring the forensic captures USING credentials it has access to that this ticket will required rolled out as part of the definition of done
  • Change to any tenant not iaas/paas

Substories:

  1. As a CSIRC analyst, working on my Axiom Magnet workstation, I can assume the right S2 role in any tenant and subscription, so that the right credentials are applied to my session.
  2. Once the right credentials are applied, the CSIRC analyst, can access the target VM and capture the disk image.
  3. Once the right credentials are applied, the CSIRC analyst can access the target VM and capture the memory image.
  4. Once the right credentials are applied, the CSIRC analyst can access the target VM and create a full clone of the VM.
  5. Once the forensic image has been captured, the CSIRC analyst can can send the captured image to the Forensic image bucket in the CSIRC tenant.
    Architecture 01
    Architecture 02
@augustincolle-digit
Copy link
Contributor

Some requests for clarification on my side for the capture only:

  • Should this action be performed by a user (manual procedure) or a function of any kind (logic app, azure function, ...)
  • How should privileges access be granted ? Auto-approved request, approval from a team leader, auto-approved only if MFA has been provided ?
  • Are there many tasks (besides capture) that must be performed on the target environment, which would require elevated privileges ?

I created a first proposal for the procedure, can you have a look and tell me if this fits:
https://webgate.ec.europa.eu/fpfis/wikis/display/CVTF/CSIRC+incident+response

@lashegu lashegu added enhancement New feature or request question Further information is requested labels Mar 24, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request question Further information is requested
Projects
None yet
Development

No branches or pull requests

3 participants