# Cloud Evidence Checklist

Provider / tenant: __________  Incident ID: __________  Collection window (UTC): __________

## Identity and control plane

- [ ] Authentication, MFA, federation, session, and risk events
- [ ] Administrative and audit activity
- [ ] Role, policy, group, key, secret, token, and service-principal changes
- [ ] New accounts, access keys, applications, OAuth grants, and trust relationships
- [ ] Organization, subscription/project/account, and logging configuration changes

## Workloads and data

- [ ] Compute, function, container, Kubernetes, and orchestration events
- [ ] Object, database, vault, snapshot, image, and backup access
- [ ] Security groups, firewalls, routes, load balancers, DNS, and flow logs
- [ ] SaaS mailbox, collaboration, file-sharing, and eDiscovery/audit records
- [ ] Provider detections and findings with raw supporting telemetry

## Preservation record

- Export method and tool version:
- Query and time-zone assumptions:
- Provider request / event IDs:
- Original format and schema:
- SHA-256 and storage location:
- Retention gaps, disabled sources, or collection limitations:
