Learn to differentiate between cloud logging mechanisms in Azure environments. This scenario tests your ability to identify the correct log source for management-plane operations during a cloud forensics investigation.

CHFI (312-49) Digital Forensics Simulation

Investigation Scenario

A multinational enterprise utilizing Microsoft Azure recently experienced a severe disruption when an entire blob container housing critical application backups was inexplicably deleted. The incident response team quickly contained the environment, but a digital forensics investigation is now underway to determine attribution.

The forensic investigator must identify the exact user account, service principal, or managed identity that executed the deletion command. The investigator needs to access the specific logging service that tracks Azure Resource Manager (ARM) actions, also known as management-plane operations.

Evidence Collected

Target Resource : Azure Storage Account (sa-corp-backups-prd) Deleted Artifact : Blob Container 'backup-critical-2026' Operation Name : Microsoft.Storage/storageAccounts/blobServices/containers/delete Forensic Objective : Extract caller identity (UPN) and source IP address. Action Type : Management-Plane Operation

Question

In a cloud-forensics case involving an Azure Storage Account, an investigator needs to identify who deleted a specific blob container. Which Azure service provides logs of management-plane operations, such as deleting a storage container?

Forensic Hint: Management-plane operations (like creating or deleting an entire resource) are tracked differently than data-plane operations (like reading or writing a specific file inside the storage). Look for the global Azure logging service that records "who did what, and when" for Azure Resource Manager (ARM).

Expert Analysis

1. What evidence shows

The scenario indicates the deletion of a blob container (an Azure resource structural element) rather than the deletion of an individual blob (the data itself). This is a management-plane operation executed via Azure Resource Manager (ARM), requiring logs that capture subscription-level administrative actions.

2. Identify forensic stage

Identification/Collection: The investigator is in the phase of identifying the correct evidentiary source (log repository) to collect data regarding the unauthorized deletion.

3. Why correct answer is correct (A)

Azure Activity Log provides insight into subscription-level events. It serves as the primary audit log for all management-plane operations (Create, Update, Delete) performed on resources in an Azure subscription. Deleting a blob container is an ARM action, and the Activity Log will record the timestamp, the identity of the caller (User Principal Name or Service Principal), the caller's IP address, and the status of the operation.

4. Why others are wrong

B. Azure Storage Analytics Logs: These logs record data-plane operations (e.g., uploading a blob, reading a blob, deleting a specific blob file). They do not track the deletion of the parent container itself.
C. Azure Monitor Metrics: Metrics provide numerical time-series data related to performance and health (e.g., CPU usage, latency, capacity), not detailed audit logs of administrative actions.
D. Azure Advisor: This is a personalized cloud consultant service that provides best practice recommendations for cost, security, and performance; it is not a logging or forensic tool.

5. Real-world forensic action

In a real-world investigation, an investigator would navigate to the Azure Portal, access the Activity Log, and filter by the "Administrative" category and the specific Storage Account resource. Because Activity Logs are only retained by default for 90 days, a crucial initial preservation step is to ensure these logs are exported to a Log Analytics Workspace or a SIEM (like Microsoft Sentinel) for long-term immutable storage.

6. MINI LESSON: Management vs. Data Plane

  • Management Plane: Controls the infrastructure. Actions include creating virtual machines, modifying network security groups, or deleting storage containers. Audited by Azure Activity Log.
  • Data Plane: Controls the data within the infrastructure. Actions include querying a SQL database, downloading a file from a storage blob, or sending a message to a queue. Audited by resource-specific diagnostic logs (e.g., Storage Analytics Logs).
  • Identity as the Perimeter: In cloud forensics, traditional IP-based attribution is secondary to Identity-based attribution. Correlating the UPN found in the Activity Log with Azure AD (Entra ID) sign-in logs is a critical step in building the chain of events.

Ready for the next case?

Explore more CHFI simulations and master the digital forensics lifecycle.

Explore more CHFI simulations