The container is gone. The API call it made isn't — if you enabled logging first.
Your first instinct on a compromised host is to image the disk. On a compromised cluster, that instinct gets you nowhere — the pod that mattered was recycled by the scheduler before you finished reading the alert. Nugget starts you where the evidence actually lives now: audit logs, API call records, and the identity that made them.
Most of this domain is a mental model swap, not a new toolkit. You already know order of volatility; here it's compressed to minutes, and the question shifts from 'which box was hit' to 'which credential, which role, which API calls, from which source IP.' Nugget sketches the identity chain — IAM user, assumed role, session token — and works you through untangling who did what, rather than handing you a diagram to admire.
It also won't let you skip the question that decides whether an investigation is even possible: was logging on before the incident. No CloudTrail in that region means no investigation, full stop, and Nugget makes you sit with that constraint instead of gliding past it.
Start exploring Cloud-Native Incident Response & Forensics tonight — a 30-day trial, cancel anytime.
Start your 30-day trial