What is a shared link?¶
A shared link is a web link that provides access to a cloud file or folder.
The link may work for named users, anyone in an organisation, or anyone who possesses it.
What this means in practice¶
A link can be forwarded, copied, posted elsewhere or opened from several devices. If no login is required, the provider may record only the connection details and link activity.
The link may allow viewing, downloading, editing or uploading, depending on its permissions. It may also expire, require a password or be restricted to certain accounts.
Investigators should identify the exact link, target file or folder, creation time, creator, permissions, expiry and whether authentication was required.
A link can remain active after the original recipient no longer needs it unless it is revoked or expires.
What this does not show on its own¶
The dangerous assumption is that using the link identifies the person who received it originally.
What to do next¶
Check sharing records, access logs, IP addresses, browser or device details and any account identifiers recorded when the link was used.
Do not assume that a view or download proves who clicked the link. An IP address identifies a connection, not a person. Security scanners, preview services and automated systems may also access links.
Preserve the sharing and access records quickly where they may be short-lived. Avoid opening a live link unnecessarily because doing so may create a new access event or alert the owner.
Key takeaway
A shared link is a transferable access route, so establish its permissions and usage records without assuming the original recipient was the person who used it.