Cloud Services¶
175 investigator questions.
Use the list below or search the complete library.
- I have been given evidence involving a cloud service — where do I start?
- What is a cloud service?
- What is the difference between cloud storage, cloud computing and a cloud account?
- Where is cloud data actually stored?
- Does “in the cloud” mean the data is stored in one place?
- What is the difference between cloud data and data stored on a device?
- What types of cloud service might appear in an investigation?
- Who is the cloud provider?
- Who is the customer or account holder?
- Who is the actual user of the cloud service?
- Can several people use the same cloud account?
- Can one person use several cloud accounts?
- Can a cloud account be accessed from several devices?
- What does a cloud record actually prove?
- Does a cloud account identify a person?
- How is a cloud account created?
- What identifiers might a cloud account use?
- What is a tenant, organisation or workspace?
- What is the difference between a personal and organisational cloud account?
- What is a cloud administrator?
- What is the difference between an administrator, account owner and ordinary user?
- What is cloud authentication?
- What is single sign-on in a cloud environment?
- What is federated identity?
- What is multi-factor authentication in a cloud service?
- Does a successful cloud login prove who logged in?
- Could somebody access a cloud account without knowing the password?
- What is a cloud session?
- What is an access token?
- What is a refresh token?
- Can a cloud session remain active after a password changes?
- What are trusted devices in a cloud account?
- What are remembered browsers or persistent sessions?
- Can an application access the cloud account on the user’s behalf?
- What is delegated access?
- What is service-account access?
- What is an API key and why might it matter?
- What is a cloud-account compromise?
- How might an investigator recognise unauthorised cloud access?
- Could a cloud account be compromised without the password being stolen?
- What is consent phishing?
- What is malicious OAuth access?
- What is session-token theft?
- What is impossible-travel detection?
- Does an unusual-location alert prove compromise?
- What is a suspicious-login alert?
- Can legitimate activity look suspicious to a cloud provider?
- Could an attacker create new users or administrators?
- Could an attacker create access that survives a password reset?
- What is cloud persistence?
- What evidence might show that a cloud account was taken over?
- What should I do if I suspect an active cloud compromise?
- What is cloud storage?
- What is the difference between a cloud file and a local file?
- Can the same file exist on several devices and in the cloud?
- What does synchronisation mean in cloud storage?
- Could a file appear on a device without being created there?
- Could a file exist in the cloud but not on the device?
- Could a file exist on the device but not in the cloud?
- What is an offline cloud file?
- What is a synced folder?
- What is a shared folder?
- What is a shared link?
- Does access to a shared link identify the person who used it?
- Can a shared link be forwarded to somebody else?
- What is the difference between viewing, editing, downloading and sharing a file?
- Does a download record prove the file was opened?
- Does a view record prove the user read or understood the file?
- Can cloud files be edited by several people?
- What is file-version history?
- Can version history show who changed a file?
- What is a file owner in a cloud service?
- Does file ownership prove authorship?
- What is file metadata in a cloud environment?
- Can cloud file metadata differ from device metadata?
- Does a cloud timestamp show when the user acted?
- What is the difference between created, uploaded, modified and synchronised times?
- Could a cloud timestamp reflect automated activity?
- Could a file be uploaded automatically?
- Could a file be created by an application or service account?
- Could another linked device change the cloud record?
- Could several users edit the same document?
- What evidence might identify the session that changed a file?
- Does an account name prove who created the file?
- What should corroborate cloud-file attribution?
- What happens when a cloud file is deleted?
- Does deleting a cloud file remove it from every device?
- What is a cloud recycle bin or deleted-items folder?
- Can a deleted cloud file be recovered?
- Could an older version remain after deletion?
- Can backups retain deleted cloud data?
- Can another user retain a copy of a deleted shared file?
- What is cloud-provider retention?
- How long might a cloud provider retain records?
- What is a legal hold?
- What is a retention policy?
- Can an organisation configure automatic deletion?
- Could provider records disappear quickly?
- What is data preservation and when should I request it?
- What is a cloud audit log?
- What is an access log?
- What is an activity log?
- What is an administrator audit log?
- What is the difference between an alert and an audit record?
- What might a cloud login record contain?
- Does a successful cloud login prove who logged in?
- What does a failed cloud login prove?
- What is a cloud session identifier?
- Can the same cloud account have several active sessions?
- Could a cloud session continue after the user closes the browser?
- What is session revocation?
- What should I record about a cloud login event?
- What might a cloud IP record show?
- Does cloud geolocation prove where the user was?
- What is user-agent information in a cloud log?
- What is a device identifier in a cloud record?
- Can browser information identify the device used?
- What is application information in a cloud event?
- What is an event or correlation identifier?
- What is an API event in a cloud log?
- What is a service-account event?
- What is a token event in a cloud log?
- What is a cloud-resource identifier?
- What is a tenant identifier?
- What is a cloud-region record?
- How should I build a timeline from cloud records?
- What should I ask a cloud provider to preserve?
- What should I request from a cloud provider?
- Should I ask for raw cloud logs or a provider summary?
- What account identifiers should I include in a provider request?
- What date and time information should I include in a cloud request?
- What should I ask an organisation that controls the cloud tenant?
- What should I ask a cloud specialist to help me establish?
- How do I assess whether cloud records are complete?
- Does the absence of a cloud log entry prove the activity did not happen?
- Could cloud logging have been disabled or changed?
- What is a cloud-log export?
- What should I record when collecting cloud records?
- Could opening a cloud item alter the evidence?
- When should I seek specialist support for cloud evidence?
- How should I describe the limits of cloud evidence?
- What can cloud records prove about an account?
- What can cloud records prove about a device?
- What can cloud records prove about a person?
- Could legitimate cloud activity look suspicious?
- Could malicious cloud activity look normal?
- When is a cloud line of enquiry proportionate?
- When should I stop pursuing cloud evidence?
- How should a manager review a cloud line of enquiry?
- What should I include in a cloud-evidence decision log?
- How should I explain cloud evidence in a report?
- How should I present uncertainty in cloud attribution?
- What common mistakes should investigators avoid with cloud evidence?
- What is the overall operational approach to cloud evidence?
- What should I do first when cloud evidence may be relevant?
- How do I identify which cloud service is involved?
- How do I distinguish device evidence from cloud evidence?
- How do I identify who controls a cloud account?
- How do I identify which session performed a cloud action?
- How do I identify which device was linked to cloud activity?
- How do I decide whether cloud evidence needs urgent action?
- What should I do if a cloud account may be compromised?
- What signs may indicate cloud-account compromise?
- Could a stolen session bypass the password and multi-factor authentication?
- What is persistence in a cloud account?
- Could a connected application retain access after a password reset?
- What should I check after a cloud account has been secured?
- How should I document cloud-account containment?
- What should I check if cloud data appears to have been deleted?
- How do I identify whether cloud data was shared externally?
- What should I check when cloud data has been synchronised across devices?
- How do I identify whether cloud activity was automated?
- How do I identify whether cloud activity came from a linked third-party service?
- What should I preserve before changing cloud permissions or sharing settings?
- What is the final investigator checklist for cloud evidence?