Digital Forensics
Server Forensics for Cloud, Database and Log Evidence
Targeted, documented collection and analysis of servers, file shares, databases, AWS and Azure workloads and logs, so you can answer what happened without taking the business offline.
When you need server forensics
Server forensics is the examination of the systems a business runs on: file servers, application and database servers, cloud virtual machines and the logs they produce. You need it when the question is bigger than one laptop. A database record changed and nobody admits to it. A file share was mass-copied before a resignation. An attacker touched a cloud workload. A lawsuit requires records that live only inside an application.
This service is part of our digital forensics services practice. It covers the evidence that ordinary device imaging misses: structured data, shared storage, cloud snapshots and server, network and authentication logs. If an attack is still in progress, start with cyber incident response and we preserve evidence as part of the response.
Typical matters include:
- Suspected tampering with financial, medical, inventory or customer records.
- Data theft from a file share, SharePoint site or document system.
- Unauthorized access to an AWS or Azure account or virtual machine.
- Litigation that needs data extracted from a line-of-business application.
- Old backup tapes, CCTV recorders or IoT devices that hold the only copy of key evidence.
What we deliver
Every engagement is scoped in writing. These are the service packages we combine for server, cloud and database work:
Server or file share collection
One server or share, agreed paths up to a stated volume, collected in a targeted way with hash verification. Full physical server or RAID images, and any planned downtime, are quoted separately.
Structured database extraction
Tables, views and records exported in an agreed format, with schema documentation and consistency checks agreed in advance. Your database administrator’s time and any application licenses are separate.
AWS or Azure evidence collection
Authorized disk snapshots and exports of cloud audit and activity logs, with hashes and documentation. Storage, API, compute and data egress charges from the cloud provider are separate.
Server and network log analysis
Senior review of authentication, firewall, VPN, web server and security logs to reconstruct access and movement. We agree an initial allowance; log ingestion and platform costs are separate.
Database and application forensics
Custom schema interpretation, audit trails and transaction analysis to show who changed what, when and through which account or process.
Legacy media and special sources
Backup tapes, CCTV and DVR systems, IoT devices, unusual systems and application-specific extraction. Special hardware and outside specialist costs are quoted.
Server forensics evidence sources and their limits
NIST Special Publication 800-86 (2006), the federal guide to integrating forensic techniques into incident response, describes four phases: collection, examination, analysis and reporting. It also advises prioritizing sources by likely value, volatility and effort. Volatile data is lost when a system is powered down, and log files can be overwritten as new events occur. That is why the order of collection matters.
| Source | What it can show | What to watch |
|---|---|---|
| File server or share | File creation, modification, access permissions and bulk copying | Access dates may not be recorded; file auditing may be off |
| Database | Current records, audit tables, transaction logs, deleted-row remnants | Many databases do not log reads or old values unless configured |
| AWS CloudTrail | API calls, console sign-ins and configuration changes | As of October 2026, event history covers only the past 90 days without a trail or event data store |
| Azure activity log | Control-plane operations on subscriptions and resources | Azure keeps activity log events for 90 days unless exported |
| Cloud disk snapshots | A point-in-time copy of a virtual machine disk | Captures disk only; memory must be collected separately and first |
| Firewall, VPN and authentication logs | Who connected, from where, and when | Short rotation, mismatched clocks and gaps across devices |
How we approach AWS and Azure evidence
We follow the cloud providers’ own published guidance. The AWS Security Incident Response User Guide lists an order for EC2 instances: record instance metadata, enable termination protection and tags, take EBS snapshots, acquire memory, then decommission and isolate. It warns that live response modifies system data and that memory should be captured before isolation or shutdown. AWS also points to CloudTrail, S3 data events and VPC Flow Logs as key log sources.
Microsoft’s Azure forensics architecture describes copying OS and data disk snapshots into a separate, restricted subscription with immutable storage, computing hash values, and storing those hashes in a key vault. We apply the same principles: separate evidence storage, restricted access, hash verification and a written record of each step.
How an engagement runs
- Request and authorization. You submit the request online. The system owner, or counsel acting for them, confirms in writing that we may access the named servers, accounts and data.
- Scoping call. We map the systems, log retention, database type and any uptime constraints, then confirm scope and billing in writing.
- Preservation. Quick wins first: extend or export logs about to expire, snapshot cloud disks, and capture volatile data where it matters.
- Collection. Targeted server and share collection, database exports, cloud snapshots and log exports, each hashed and logged for chain of custody.
- Analysis. Logs, records and artifacts normalized to one time zone and correlated into a timeline.
- Reporting. Plain-language findings with stated limits, and a formal report or expert witness testimony if the matter goes to litigation.
Authority, consent and legal limits
We access servers, databases and cloud accounts only with written authorization from the owner or someone with legal authority to grant it, such as a company officer, counsel acting for the company or a court order. A former IT contractor’s leftover password is not authorization. For hosted systems, we work through the account owner’s own administrative access and the provider’s supported tools.
We do not bypass authentication we are not authorized to bypass, we do not access third-party systems such as an attacker’s server, and we do not hack back. Some cloud and hosting contracts limit what can be done or require notice; your administrator or counsel should confirm that. When data may be relevant to a lawsuit, Federal Rule of Civil Procedure 37(e) allows a court to act when electronically stored information is lost because a party failed to take reasonable steps to preserve it. This is general information, not legal advice.
How it is priced
- Server and share collection. Quoted per source, for agreed paths up to a stated volume. Physical server images, RAID rebuilds and downtime are quoted separately.
- Database, cloud and log work. Billed hourly with a short minimum, against an allowance we agree before work starts.
- Third-party costs. Cloud storage, API, compute and data egress charges are billed by your provider. Log ingestion platforms, database administrator time and application licenses are separate.
- Special sources. Tapes, CCTV and unusual systems are hourly, with hardware and outside specialist costs quoted.
Cost drivers are the number of systems, data volume, log retention, how custom the database or application is, and whether work must happen after hours to avoid downtime. Extra work is handled by written change order.
Mistakes to avoid before server forensics
- Do not restore from backup over the evidence. Snapshot or image first, then restore.
- Do not reboot or terminate a suspect cloud instance. You lose memory, and a terminated instance can take its disk with it.
- Do not let logs roll over. Check retention today and export what is close to expiring.
- Do not run your own queries against a suspect database. Ad hoc fixes and cleanup change the very records in dispute.
- Do not overwrite DVR footage. Most recorders loop. Pull the unit or stop recording on the affected channel.
- Do write down who has admin access. We need to know which accounts are trusted and which are suspect.
Who this is for
- Law firms
- IT directors and MSPs
- Healthcare and financial organizations
- Business owners
- In-house counsel
- Insurers and breach coaches
Frequently asked questions
Do you need to shut down our server to do server forensics?
Usually not. Most work is targeted collection from a running server, database exports and log exports. A full physical server or RAID image may need planned downtime, and that is quoted and scheduled with you in advance.
Can you show who changed a database record?
Often, if the database or application keeps audit tables, transaction logs or change history, and the accounts can be tied to people. Where those records do not exist, we say so and explain what other evidence may help.
How long do AWS and Azure keep logs?
As of October 2026, AWS CloudTrail event history covers the past 90 days of management events, and Azure keeps activity log events for 90 days, unless you have set up a trail or export. Check retention right away.
Who pays the cloud provider charges during collection?
Snapshot storage, API, compute and data egress charges are billed to your account by your provider. They are separate from our fees, and we estimate them during scoping.
Can you recover deleted data from a server or database?
Sometimes. Snapshots, backups, transaction logs and unallocated space can hold remnants. No recovery is guaranteed, and the chances drop the longer a busy system keeps writing new data.
Is remote collection good enough for court?
Remote collection can be court-ready when it is documented, hash-verified and repeatable. Whether evidence is admitted is up to the court. We document every step so the method can be explained.
Can you pull footage from an old DVR or data from a backup tape?
In many cases, yes, through our legacy media and special sources service. Some formats need special hardware or outside specialist work, which we quote before starting.
Related guides
- Database forensics and proving SQL tampering
- Enterprise cloud forensics for SaaS and IaaS evidence
- Network intrusion forensics after a breach
- How Linux servers get hacked
- CCTV and DVR video forensics
- Forensic imaging and chain of custody
- Remote forensic extraction service
- Cyber incident response service
- eDiscovery and litigation support
We access servers, databases and cloud accounts only with written authorization from the owner or a court order. This is general information, not legal advice.
Sources: NIST SP 800-86, AWS: Collect relevant artifacts, AWS CloudTrail event history, Microsoft Azure forensics chain of custody, Azure activity log, CISA et al.: Event logging best practices (2024).
Preserve the server evidence before it rolls over
Request this service online and select server, cloud or database forensics on the form. It goes straight to our cyber and forensics lead, the specialist who handles these cases, so there is no phone tag and we can tell you what to snapshot or export first. If an attacker is active or logs are about to expire, use our urgent intake form.