Skip to content
CIM-262 Cyber Incidents & Offender Methods

What is abuse of a trusted cloud service?

Abuse of a trusted cloud service occurs when an offender uses a legitimate provider for malicious storage, communication, execution, identity or delivery.

Evidential caution: that traffic to a well-known provider is benign.

What this means

An offender may abuse:

cloud storage;

serverless functions;

code repositories;

messaging APIs;

collaboration platforms;

identity providers;

content-delivery services;

webhooks;

online documents.

the exact provider;

account or tenant;

object, function or channel;

source process;

authentication;

timestamps;

content;

provider-side actions;

linked victim activity.

A connection to the provider alone is weak evidence because many legitimate applications use the same service.

The specific account, object and action matter.

The account may have been created using false details, compromised or rented.

Provider-specific retention and audit behaviour should be checked during casework.

Trusted cloud services may also conceal the destination behind provider domains, shared addresses and encrypted traffic. Preserve object names, account identifiers, request paths and API actions. A broad statement that traffic went to a major cloud provider is usually too imprecise to establish malicious use.

================================================================================

What to check or do next

  • Investigators should establish:
  • Record that control history explicitly.
  • Record that control history explicitly and separately. The operational takeaway is:
  • Identify the exact cloud account, object and action, and separate trusted provider traffic from authorised use and offender identity.

Evidential limits

It may not be.

Do not assume the provider knowingly supported the offence.

Where the cloud account is compromised, preserve recovery-email changes, token creation, API keys, application passwords and sharing activity. The legitimate account owner may be another victim, and current ownership may not reflect who controlled the account during the incident.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.