CHFI (312-49) Digital Forensics Simulation
Investigation Scenario
You have been engaged as a digital forensic investigator following a severe outage in a client's Microsoft Azure environment. A critical production Virtual Machine (VM) hosting an unbacked-up database was deleted outside of normal change management windows.
The incident response team has secured the Azure Activity Logs corresponding to the time of the deletion. To establish attribution and prove non-repudiation, you must parse the JSON schema of the deletion event to identify the exact account (User Principal Name or Service Principal) responsible for initiating the Azure Resource Manager (ARM) API call.
Evidence Collected
You extract the relevant log entry representing the VM deletion event from the Azure Activity Log via Azure Monitor. Review the structure below:
Question
During a cloud-forensics investigation in Azure, an analyst is reviewing the Azure Activity Log to identify who deleted a virtual machine. Which field in the activity log entry provides the identity of the user who performed the action?
Expert Analysis
1. What the Evidence Shows
The JSON excerpt from the Azure Activity Log confirms a successful (status: Succeeded) deletion operation (Microsoft.Compute/virtualMachines/delete) on a specific resource (prod-db-01). Crucially, the top-level key caller contains the value admin-svc@corp.onmicrosoft.com, identifying the exact identity context used to execute the destructive API call from IP 203.0.113.45.
2. Identify Forensic Stage
Analysis (Attribution). The evidence has been collected; the investigator is currently analyzing the parsed artifacts to reconstruct the timeline and establish non-repudiation (identifying the attacker or compromised insider).
3. Why the Correct Answer is Correct (A)
A. caller: In the official Microsoft Azure Activity Log schema, the caller field is specifically designated to hold the identity (the User Principal Name or Service Principal Name) of the user or application that initiated the request to the Azure Resource Manager (ARM). This is the primary field an investigator relies on for attribution.
4. Why Others are Wrong
- B. claims: The
claimsfield contains the payload of the JSON Web Token (JWT) used for authorization (e.g., audience, issuer, issued-at time). While it contains deep authentication metadata, it is not the primary, top-level field designed to directly expose the user's identity name in standard log reviews. - C. properties: The
propertiesobject contains contextual, service-specific details about the event (like status codes or sub-statuses), but it does not contain the identity of the user. - D. httpRequest: The
httpRequestobject contains network-level metadata, such as theclientIpAddressand HTTPmethod. While vital for tracking the origin of the attack, it does not identify the authenticated user account.
5. Real-World Forensic Action
Upon identifying the caller as a service account (admin-svc@corp.onmicrosoft.com), the investigator would immediately pivot. They would cross-reference the `clientIpAddress` against known organizational subnets, and then query Azure Active Directory (Entra ID) Sign-in Logs to determine where and how the service account credentials were recently authenticated, potentially uncovering a broader credential theft scenario.
6. MINI LESSON: Cloud Artifact Anatomy
- Evidence Interpretation: Cloud control-plane logs differ vastly from traditional OS logs. Mastery requires memorizing the schemas (AWS CloudTrail vs. Azure Activity Logs).
- Separation of Network and Identity: In cloud forensics, the IP address (
httpRequest) and the Identity (caller) are distinct. A trusted identity can be abused from a malicious IP, or a trusted IP can be used to authenticate a compromised identity. - Chain of Custody: Azure Activity Logs are retained for 90 days by default. For forensic viability, they must be continuously exported to immutable blob storage or a secure Log Analytics Workspace.
Explore more CHFI simulations
Sharpen your digital forensics skills with more realistic scenarios.
View Practice Tests