What is the overall operational approach to cloud evidence?¶
Treat cloud evidence as a connected set of provider, tenant, application and device records. Define the decision, protect volatile sources, reconstruct the technical activity and corroborate any conclusion about the person responsible.
Work from a question, not an account dump¶
Identify the service, tenant, accounts, applications, resources and possible devices. Ask what the evidence could establish: account control, session origin, sharing, deletion, automation or a link to physical-device activity.
Map the evidence holders. Providers may retain account and platform events; tenant organisations may hold administration, security and configuration records; devices may hold local files, tokens, browser artefacts and sync data.
Preserve, connect and test¶
Protect short-lived records before unnecessary live interaction. Retain original exports, stable identifiers and source timestamps. Link authentication, sessions, tokens, applications, APIs and resource events while distinguishing user action from automation and provider processing.
Test account sharing, compromise, remote access and alternate devices. Corroborate technical activity with device, organisational and real-world evidence. State what each source proves and the limitations of the collection.
Keep the enquiry controlled¶
Assign actions for preservation, provider contact, tenant collection and specialist analysis. Set review points and stop conditions. New evidence should change the working theory where necessary rather than being forced into the first explanation.
The point to remember
Cloud investigation is a controlled process of defining the question, preserving sources, joining technical records and testing attribution against independent evidence.