question

tiptiptip avatar image
0 Votes"
tiptiptip asked tiptiptip commented

Do Azure provide compability to dump full memory from Azure VM for digital forensics?

I recently came across a article and it seems there is a way for Azure support to acquire full memory dump.
https://azure.microsoft.com/en-us/support/legal/support-diagnostic-information-collection/

Wonder if there is a way for customer to submit Azure support request to gain access to full memory dump file for digital forensics?

azure-virtual-machines
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

prmanhas-MSFT avatar image
0 Votes"
prmanhas-MSFT answered tiptiptip commented

@tiptiptip Apologies for the delay in response and all the inconvenience caused because of the issue.

You can refer to below link for more info:

https://heranonazure.wordpress.com/2018/09/26/created-a-dump-for-a-running-vm-in-azure/

Also this thread on Q&A might be helpful as well.

Hope it helps!!!

Please "Accept as Answer" if it helped so it can help others in community looking for help on similar topics.



· 5
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@prmanhas-MSFT, Thanks for your reply!

We are exploring option for Digital Forensics (To capture memory dump from Azure backend instead of doing it inside VM host).
I have the following questions:

0 Votes 0 ·

@tiptiptip Thank you for your response!!!

Let me check internally and I will keep you posted on update.

Thanks

0 Votes 0 ·

Thanks! @prmanhas-MSFT

0 Votes 0 ·

@tiptiptip Apologies for all the delay in response and all the inconvenience caused because of the issue!!!

I had discussion internally and they did confirm that customer do not have access to those dumps as per your requirement. There are alot of factors involved which include security reason as well which won't fit with one compliance.

They can guide you through it again condition being that you have some privileged Admin. role in directory to do so but that can be suggested over call with Support.

Hence I would suggest you to open Support Request if you need further explanation and have support Plan in place otherwise do let me know I can enable One Time Free Technical Support for you.

Hope it helps!!!

Please "Accept as Answer" if any of above helped so it can help others in community looking for help on similar topics.




0 Votes 0 ·

Thanks for your information.

0 Votes 0 ·