I have been given material involving a cloud service
Identify the service, account, object and stable identifiers before treating the visible file as the whole record. Permissions, versions, access events and synchronised devices may each explain part of its history.
Start with what needs doing now
Use this route when cloud material may change, be deleted or remain available through several accounts, sessions and devices.
Move from visible files to stable objects, permissions, versions, access records, synchronised devices and a defensible suspect.
Reference CLD-000Preserve provider dataWhen should I request preservation?Identify the account, object, period and records at risk before provider retention or user action changes what remains.
Reference CLD-098SpeedCould provider records disappear quickly?Recognise short retention, deletion and changing access while useful provider records may still be obtainable.
Reference CLD-097Understand the evidence and the offender method
Use this route to understand cloud objects and their histories, then see those same functions used inside a separate offender operation.
Understand objects, accounts, permissions, versions and service events without overstating personal attribution.
Reference CLD-001Separate offender exampleDodgy Dave puts illegal waste disposal in the shared calendarFollow a separate illegal-waste operation through shared folders, version history, synchronisation and participant activity.
Reference CLD-175Go directly to the issue you need to resolve
Identify owners, members, permissions and the actions available to each.
Reference CLD-061HistoryWhat is file-version history?Use earlier versions and save events to understand how an object changed.
Reference CLD-069Multiple devicesCan a cloud account be accessed from several devices?Separate account activity from the particular session and device involved.
Reference CLD-012AttributionWhat should corroborate cloud-file attribution?Test account events against devices, communications and surrounding conduct.
Reference CLD-084Browse every Cloud services guidance page
The complete reference library remains available when you need a narrower question.- I have been given evidence involving a cloud service - where do I start?
- What is a cloud service?
- What is the difference between cloud storage, cloud computing and a cloud account?
- Where is cloud data actually stored?
- Does “in the cloud” mean the data is stored in one place?
- What is the difference between cloud data and data stored on a device?
- What types of cloud service might appear in an investigation?
- Who is the cloud provider?
- Who is the customer or account holder?
- Who is the actual user of the cloud service?
- Can several people use the same cloud account?
- Can one person use several cloud accounts?
- Can a cloud account be accessed from several devices?
- What does a cloud record actually prove?
- Does a cloud account identify a person?
- How is a cloud account created?
- What identifiers might a cloud account use?
- What is a tenant, organisation or workspace?
- What is the difference between a personal and organisational cloud account?
- What is a cloud administrator?
- What is the difference between an administrator, account owner and ordinary user?
- What is cloud authentication?
- What is single sign-on in a cloud environment?
- What is federated identity?
- What is multi-factor authentication in a cloud service?
- Does a successful cloud login prove who logged in?
- Could somebody access a cloud account without knowing the password?
- What is a cloud session?
- What is an access token?
- What is a refresh token?
- Can a cloud session remain active after a password changes?
- What are trusted devices in a cloud account?
- What are remembered browsers or persistent sessions?
- Can an application access the cloud account on the user’s behalf?
- What is delegated access?
- What is service-account access?
- What is an API key and why might it matter?
- What is a cloud-account compromise?
- How might an investigator recognise unauthorised cloud access?
- Could a cloud account be compromised without the password being stolen?
- What is consent phishing?
- What is malicious OAuth access?
- What is session-token theft?
- What is impossible-travel detection?
- Does an unusual-location alert prove compromise?
- What is a suspicious-login alert?
- Can legitimate activity look suspicious to a cloud provider?
- Could an attacker create new users or administrators?
- Could an attacker create access that survives a password reset?
- What is cloud persistence?
- What evidence might show that a cloud account was taken over?
- What should I do if I suspect an active cloud compromise?
- What is cloud storage?
- What is the difference between a cloud file and a local file?
- Can the same file exist on several devices and in the cloud?
- What does synchronisation mean in cloud storage?
- Could a file appear on a device without being created there?
- Could a file exist in the cloud but not on the device?
- Could a file exist on the device but not in the cloud?
- What is an offline cloud file?
- What is a synced folder?
- What is a shared folder?
- What is a shared link?
- Does access to a shared link identify the person who used it?
- Can a shared link be forwarded to somebody else?
- What is the difference between viewing, editing, downloading and sharing a file?
- Does a download record prove the file was opened?
- Does a view record prove the user read or understood the file?
- Can cloud files be edited by several people?
- What is file-version history?
- Can version history show who changed a file?
- What is a file owner in a cloud service?
- Does file ownership prove authorship?
- What is file metadata in a cloud environment?
- Can cloud file metadata differ from device metadata?
- Does a cloud timestamp show when the user acted?
- What is the difference between created, uploaded, modified and synchronised times?
- Could a cloud timestamp reflect automated activity?
- Could a file be uploaded automatically?
- Could a file be created by an application or service account?
- Could another linked device change the cloud record?
- Could several users edit the same document?
- What evidence might identify the session that changed a file?
- Does an account name prove who created the file?
- What should corroborate cloud-file attribution?
- What happens when a cloud file is deleted?
- Does deleting a cloud file remove it from every device?
- What is a cloud recycle bin or deleted-items folder?
- Can a deleted cloud file be recovered?
- Could an older version remain after deletion?
- Can backups retain deleted cloud data?
- Can another user retain a copy of a deleted shared file?
- What is cloud-provider retention?
- How long might a cloud provider retain records?
- What is a legal hold?
- What is a retention policy?
- Can an organisation configure automatic deletion?
- Could provider records disappear quickly?
- What is data preservation and when should I request it?
- What is a cloud audit log?
- What is an access log?
- What is an activity log?
- What is an administrator audit log?
- What is the difference between an alert and an audit record?
- What might a cloud login record contain?
- Does a successful cloud login prove who logged in?
- What does a failed cloud login prove?
- What is a cloud session identifier?
- Can the same cloud account have several active sessions?
- Could a cloud session continue after the user closes the browser?
- What is session revocation?
- What should I record about a cloud login event?
- What might a cloud IP record show?
- Does cloud geolocation prove where the user was?
- What is user-agent information in a cloud log?
- What is a device identifier in a cloud record?
- Can browser information identify the device used?
- What is application information in a cloud event?
- What is an event or correlation identifier?
- What is an API event in a cloud log?
- What is a service-account event?
- What is a token event in a cloud log?
- What is a cloud-resource identifier?
- What is a tenant identifier?
- What is a cloud-region record?
- How should I build a timeline from cloud records?
- What should I ask a cloud provider to preserve?
- What should I request from a cloud provider?
- Should I ask for raw cloud logs or a provider summary?
- What account identifiers should I include in a provider request?
- What date and time information should I include in a cloud request?
- What should I ask an organisation that controls the cloud tenant?
- What should I ask a cloud specialist to help me establish?
- How do I assess whether cloud records are complete?
- Does the absence of a cloud log entry prove the activity did not happen?
- Could cloud logging have been disabled or changed?
- What is a cloud-log export?
- What should I record when collecting cloud records?
- Could opening a cloud item alter the evidence?
- When should I seek specialist support for cloud evidence?
- How should I describe the limits of cloud evidence?
- What can cloud records prove about an account?
- What can cloud records prove about a device?
- What can cloud records prove about a person?
- Could legitimate cloud activity look suspicious?
- Could malicious cloud activity look normal?
- When is a cloud line of enquiry proportionate?
- When should I stop pursuing cloud evidence?
- How should a manager review a cloud line of enquiry?
- What should I include in a cloud-evidence decision log?
- How should I explain cloud evidence in a report?
- How should I present uncertainty in cloud attribution?
- What common mistakes should investigators avoid with cloud evidence?
- What is the overall operational approach to cloud evidence?
- What should I do first when cloud evidence may be relevant?
- How do I identify which cloud service is involved?
- How do I distinguish device evidence from cloud evidence?
- How do I identify who controls a cloud account?
- How do I identify which session performed a cloud action?
- How do I identify which device was linked to cloud activity?
- How do I decide whether cloud evidence needs urgent action?
- What should I do if a cloud account may be compromised?
- What signs may indicate cloud-account compromise?
- Could a stolen session bypass the password and multi-factor authentication?
- What is persistence in a cloud account?
- Could a connected application retain access after a password reset?
- What should I check after a cloud account has been secured?
- How should I document cloud-account containment?
- What should I check if cloud data appears to have been deleted?
- How do I identify whether cloud data was shared externally?
- What should I check when cloud data has been synchronised across devices?
- How do I identify whether cloud activity was automated?
- How do I identify whether cloud activity came from a linked third-party service?
- What should I preserve before changing cloud permissions or sharing settings?
- What is the final investigator checklist for cloud evidence?
- Dodgy Dave puts illegal waste disposal in the shared calendar