- Stop the instance immediately.
- Take a snapshot of the EBS Volume.
- Deploy the instance in to an isolated environment.
- Isolate VPC, ensure no internet access.
- Access the instance using a Forensic Instance.
- Review the logs for the next steps.
- Perform the forensic analysis.
Archives
April 2020
Categories |