top of page


The Big Data Blog


Speaking AWS — The Language Every IR Investigator Needs to Know
If you've ever walked into an AWS incident and felt like the engineers around you were speaking a completely different language — you're not alone. AWS has its own vocabulary, its own structure, and its own quirks. Before you can even begin to scope an investigation, you need to understand what you're actually dealing with. Think of this article as your field translator. We're going to walk through how AWS is organised, how identity works, and the different ways someone — leg
Jun 256 min read


When One Alert Tells You Everything — and Nothing (Detecting v17 Lumma Stealer)
The Attacker Almost Won On a quiet Tuesday morning in June 2026, an employee at a mid-size organization pressed Win+R, pasted a command they found on a website, and hit Enter. By the time SentinelOne surfaced its first alert, Lumma Stealer had already spent over five minutes inside the machine — reading browser memory, querying the Windows credential database, capturing keystrokes, and probing the network for other machines to move to. The user had no idea. They spent the nex
Jun 148 min read
They Tried to Erase Everything. Here's How It Almost Worked.
An attacker silenced the EDR agent, waited weeks, dropped a hidden payload, then fired off a command designed to wipe every byte on the server. One thing stood between them and total data destruction.
Jun 140 min read


In-Cloud IR: How to Forensically Acquire and Analyze a Compromised Azure VM Without Pulling the Plug
Traditional digital forensics has a straightforward playbook for compromised machines: pull the drive, image it, analyze the image. In cloud environments that approach does not work. You cannot physically pull a disk from a data center you do not have physical access to. Downloading a full virtual disk over the internet for a 512GB drive takes hours and costs a significant amount in egress fees. And shutting down the VM disrupts the business and may destroy volatile evidence.
Jun 29 min read


VM-Level Forensics in Azure: Collecting Windows, Linux, and Application Logs Without Logging Into the Machine
Network logs tell you what traffic hit a machine. Activity logs tell you when it was created and modified. But neither tells you what happened inside the operating system — which processes ran, which accounts authenticated locally, which files were accessed. For that level of detail, you need OS-level logs, and in Azure collecting those requires an agent running on the VM itself. The upside is significant: Azure's diagnostic agent lets you pull Windows event logs and Linux sy
Jun 17 min read
Ready to discuss:
- Schedule a call for a consultation
- Message me via "Let's Chat" for quick questions
Let's connect!
bottom of page