Cloud Log Sources That Save Cases
What to collect and retain, before you need it

Practical Guide Free to Use

Investigations don't fail because the analysis is hard. They fail because the logs are gone. Default cloud retention is built for billing disputes, not breach timelines, and the gap between the two is where cases die.

The Sources That Decide Cases

When we reconstruct an incident, these are the logs that answer the questions legal, insurance, and the board will ask.

Source What It Proves The Trap
M365 Unified Audit Log Who touched what across Exchange, SharePoint, Teams. The backbone of any M365 investigation. Default retention is measured in months, not years. Verify auditing is actually enabled for all mailboxes.
Identity Sign-In Logs Every login: source IP, device, MFA result. This is how you separate the attacker from the employee. Entra ID default retention can be as short as 7–30 days. Export or stream to a SIEM.
Mailbox Audit + Message Trace What the attacker read, searched, forwarded, and deleted inside a compromised mailbox. Message trace detail ages out in weeks. In BEC cases, export on day one.
OAuth / App Consents Persistent access granted to third-party and attacker-controlled apps. Survives password resets. Almost nobody reviews these until an IR team asks for them.
EDR Telemetry Process trees, lateral movement, tooling. The ground truth of what ran where. Rolling buffers overwrite fast. If EDR isn't deployed before the incident, that history never existed.
Cloud Control Plane AWS CloudTrail / Azure Activity / GCP Audit: who changed infrastructure, created keys, opened access. Data-plane events (object reads, downloads) are often NOT logged by default.
VPN / Firewall / RMM Initial access and exfiltration paths, the perimeter story that corroborates everything else. Appliance local storage wraps in days. If it's not shipped elsewhere, it's gone.
Backup System Logs Whether backups were accessed, altered, or deleted. Increasingly the attacker's first stop. Proving backup integrity matters for both recovery decisions and the insurance claim.

Enable This Week

Four moves, minimal cost, disproportionate payoff the day something goes wrong.

1

Verify, Don't Assume

Confirm audit logging is on for every mailbox and workload. "It should be on by default" has lost more cases than any attacker.

2

Extend Retention

Push critical sources to 12 months via licensing, SIEM, or cheap cold storage. Dwell time regularly exceeds default retention.

3

Centralize It

Ship identity, email, EDR, and perimeter logs to one place the attacker can't edit.

4

Test a Pull

Time how long it takes to export 90 days of sign-in logs. If the answer is "open a ticket," fix that before the incident.

On day one of an incident: export first, analyze second. Logs age out while you investigate. See BEC: The First 24 Hours.

Not Sure What You'd Have?

Most organizations discover their logging gaps during an incident, the most expensive possible time. Olympus Cyber assesses evidence readiness as part of executive resilience engagements: what you'd have, what you'd wish you had, and the shortest path between the two.
🚨 Emergency IR