Skip to the card

Card 070 of 9832026-09-30 issue

Observed arrival · 2026-09-30

Azure Forensics, in your browser

azureforensics.app Visit website
Editorial interest 84/100 Selection signal · not a rating of the site

A free browser-based tool for triaging exported Azure logs for signs of a subscription compromise.

Landing page captured for the 2026-09-30 issue.
For
Azure administrators investigating suspected subscription compromise
Worth noticing
The collection guide warns that portal CSV exports drop caller IPs and some diagnostic logs may not exist unless enabled before the incident.

Field notes

The collection walkthrough shows a Cloud Shell route: export Activity Logs for enabled subscriptions, optionally retrieve Defender for Cloud alerts, then zip the files for analysis. It also accepts folders and compressed exports, including .gz files. The page cautions that Activity Log retention is limited to 90 days, diagnostic logs depend on earlier settings, and some export paths can omit caller IPs or return only partial results.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central

One card from the complete issue

Ask the Descendants

390,826 arrived 1,000 judged 983 catalogued Enter the complete issue
azureforensics.app

Landing page observed 2026-09-30. The live site may have changed.