Cloud Log Sources That Save Cases
What to collect and retain, before you need it
Investigations don't fail because the analysis is hard. They fail because the logs are gone. Default cloud retention is built for billing disputes, not breach timelines, and the gap between the two is where cases die.
The Sources That Decide Cases
When we reconstruct an incident, these are the logs that answer the questions legal, insurance, and the board will ask.
| Source | What It Proves | The Trap |
|---|---|---|
| M365 Unified Audit Log | Who touched what across Exchange, SharePoint, Teams. The backbone of any M365 investigation. | Default retention is measured in months, not years. Verify auditing is actually enabled for all mailboxes. |
| Identity Sign-In Logs | Every login: source IP, device, MFA result. This is how you separate the attacker from the employee. | Entra ID default retention can be as short as 7–30 days. Export or stream to a SIEM. |
| Mailbox Audit + Message Trace | What the attacker read, searched, forwarded, and deleted inside a compromised mailbox. | Message trace detail ages out in weeks. In BEC cases, export on day one. |
| OAuth / App Consents | Persistent access granted to third-party and attacker-controlled apps. Survives password resets. | Almost nobody reviews these until an IR team asks for them. |
| EDR Telemetry | Process trees, lateral movement, tooling. The ground truth of what ran where. | Rolling buffers overwrite fast. If EDR isn't deployed before the incident, that history never existed. |
| Cloud Control Plane | AWS CloudTrail / Azure Activity / GCP Audit: who changed infrastructure, created keys, opened access. | Data-plane events (object reads, downloads) are often NOT logged by default. |
| VPN / Firewall / RMM | Initial access and exfiltration paths, the perimeter story that corroborates everything else. | Appliance local storage wraps in days. If it's not shipped elsewhere, it's gone. |
| Backup System Logs | Whether backups were accessed, altered, or deleted. Increasingly the attacker's first stop. | Proving backup integrity matters for both recovery decisions and the insurance claim. |
Enable This Week
Four moves, minimal cost, disproportionate payoff the day something goes wrong.
Verify, Don't Assume
Confirm audit logging is on for every mailbox and workload. "It should be on by default" has lost more cases than any attacker.
Extend Retention
Push critical sources to 12 months via licensing, SIEM, or cheap cold storage. Dwell time regularly exceeds default retention.
Centralize It
Ship identity, email, EDR, and perimeter logs to one place the attacker can't edit.
Test a Pull
Time how long it takes to export 90 days of sign-in logs. If the answer is "open a ticket," fix that before the incident.
On day one of an incident: export first, analyze second. Logs age out while you investigate. See BEC: The First 24 Hours.