Skip to content
Skip to main content
Cloud Services Investigation walkthrough

I have been given evidence involving a cloud service. What happens next?

Leila Morgan reports that her former partner, Marcus Venn, quoted from a private relocation document and changed figures in a household budget after they separated. Both files sit in cloud folder F-2804, which they once shared. This walkthrough shows how objects, permissions, versions and access records can evidence coercive and controlling conduct and take the enquiry from a cloud account towards a suspect.

The working principle
Identify the object and its history, not merely the file Leila can see today. A cloud folder can retain stable identifiers, earlier versions, sharing permissions and access events that explain what changed, which account acted and where personal attribution should be tested.
Victim's account
Stable folder and objects
Permissions
Versions
Access events
Synchronised device
Suspect

The account, folder, permission, session, device and human are separate propositions. Their value grows when independent records agree on the same objects, actions and times.

The material received

What Leila supplies
Cloud folderHome records, visible under account C-54119.
Reported documentsrelocation-plan.docx and household-budget.xlsx.
ConductMarcus quoted a private sentence at 21:18 UTC and the budget changed later that evening.
Available contextOriginal messages, security notification and a provider export requested through the account.

Leila's screenshot establishes what the folder displayed to her. The provider export supplies folder F-2804, object OBJ-4407 and version identifiers that remain stable when the visible filename changes. A shared link or folder view is often only the entrance to that provider history.

Initial cloud record
folder_id=F-2804object_id=OBJ-4407filename=relocation-plan.docxcurrent_version=V-12owner_account=C-54119editor_account=C-77503
Established the service associates these accounts, permissions and versions with the objectStill open who controlled account C-77503 during the reported activity
EstablishedLeila's account owned the folder and account C-77503 retained editor access after the relationship ended.
Still openWhat the account accessed or changed, who used it, and how those actions relate to Marcus's messages and wider conduct.

Work the cloud material as evidence

01 · Preserve the visible material and stable identifiers

The two reported filenames sit inside folder F-2804 as objects OBJ-4407 and OBJ-4412, each with a version history.

Preserve Leila's original screenshots, messages and security notification, but do not treat a download as the whole cloud record. Cloud metadata can differ from device metadata, and a locally saved file may acquire a new created date without changing the provider's object history.

Record the account, folder, object, version and share identifiers. Consider cloud preservation promptly where deletion or changing permissions may affect what remains available.

Investigator action
Retain the original report and messages; record the provider, account, folder, object, version and permission identifiers; and preserve the service-side history rather than relying only on downloaded copies.

02 · Establish what changed and when

Version history shows C-77503 opening the relocation plan and changing the budget within the period described by Leila.

9 July · 21:06:14Session SES-6B81 views object OBJ-4407 version V-12.
21:18:09Message from Marcus quotes a sentence unique to V-12.
21:24:37The same session saves version V-19 of budget object OBJ-4412.

File-version history records the sequence of changes and the service account involved. It does not prove the account holder authored every alteration. Here, the unique quoted sentence and close timing are strong corroboration because the cloud and messaging services record different parts of the same conduct.

03 · Read the permissions as a history

Marcus's account had been granted editor access during the relationship; later events show that permission being used and extended to another account.

A shared folder can allow viewing, editing, downloading or further sharing depending on the permission. The fact that Leila originally granted access explains how the account could reach the files; it does not answer whether later use formed part of coercive or controlling conduct.

Permission history for F-2804
OwnerC-54119 · Leila Morgancreated folder and retained ownership
EditorC-77503 · Marcus Vennpermission granted 14 February; still active on 9 July
Further shareC-66308added by session SES-6B81 at 21:31:42
Permission records establish account actions; purpose and human responsibility require wider evidence

A public or forwarded link can reach people not named in the visible folder. Why shared links can travel explains why provider access events and the permission history matter more than assumptions about who Leila intended to include.

04 · Work the account and access events

Account C-77503 is registered to Marcus, and the relevant session used his recurring application identifier from a connection associated with his address.

The customer record gives a direct line of enquiry, not final attribution. A successful cloud login establishes that the service accepted the credentials or authentication presented; it does not see the person holding the device.

Here, session SES-6B81 uses application identifier APP-2F71, previously associated with Marcus's account over several months. The source address is allocated to the service at his address at the relevant time. Those records substantially strengthen the account connection while leaving possession and control to be tested.

05 · Connect the cloud history to a device and the reported conduct

A tablet recovered from Marcus contains a synchronised copy of folder F-2804, the relevant application identifier and local versions matching the provider records.

Synchronisation can place cloud material onto a device automatically, so the existence of a local copy alone does not prove it was deliberately opened. In this case the tablet also records the active session, recent access to both objects and the message sent minutes later quoting text unique to version V-12.

The provider's folder, version, permission and session records now align with Leila's messages and the recovered device. This is a strong circumstantial route to Marcus: independent sources connect him to the account, device, private information, alteration and communication. The enquiry can be positive about that strength while still testing whether somebody else used the account and what Marcus says the activity meant.

EstablishedMarcus-associated account, connection and device evidence converges on access to Leila's private material, the budget change and the quoted message.
Still openMarcus's explanation, the purpose and wider course of conduct, the role of account C-66308, and any other person with access to the tablet.

Where this leaves the investigation

Cloud historyStable object, version and permission records explain what was accessed, changed and shared.
CorroborationThe quoted sentence and message time independently align with the cloud-view event.
Primary suspectAccount, network, application and recovered-device evidence provide a strong route to Marcus Venn.
Wider conductTest the purpose, the additional recipient and how these events fit the reported pattern of coercive and controlling behaviour.
Operational takeaway
Cloud evidence is a history of objects, permissions and events - not merely a folder of files. Preserve stable identifiers, work the version and sharing records and use independent communications and device evidence to move confidently from an account event towards a suspect.
Reference: CLD-000Cloud Services