SKIP TO CONTENT
SERVICE LINE / CLOUD FORENSICSS-03

Cloud Forensics Expert Witness Services

Collection and analysis of evidence that exists only inside someone else's infrastructure — tenant audit records, identity logs, control-plane events, and object storage — collected through authenticated API access, hashed on receipt, and documented so that provenance survives the same scrutiny as a disk image.

PLATFORMS
Microsoft 365 · Google Workspace
INFRASTRUCTURE
AWS · Azure · Google Cloud
SAAS
Slack · Box · Dropbox · Salesforce
COLLECTION
Authenticated API · Tenant export
AUTHENTICATION
FRE 901(b)(9) · 902(13) · 902(14)
DELIVERABLE
FRCP 26(a)(2)(B) report
IN SHORT

Cloud forensics is the collection and analysis of evidence held by a service provider rather than on a device you can seize. There is no drive to write-block, so defensibility comes from documented provenance — which account collected what, by which query, on what date, verified by which hash — and from getting to perishable logs before their retention window closes.

What a cloud examination covers

The examiner does not own the hardware, so every record is obtained through an interface the provider controls — and the first analytical question is always what that interface does and does not return.

Where the evidence sits

  • Identity and sign-in records — authentication events, multi-factor prompts and failures, token issuance and refresh, conditional-access decisions, OAuth application consent grants, and registered devices. Anomalous consent grants and new token registrations are frequently the earliest visible sign of account compromise.
  • Productivity and mailbox audit records — the Microsoft 365 unified audit log and mailbox auditing, including per-item access events on higher licence tiers; message trace; inbox-rule and forwarding changes; Google Workspace admin, login, and Drive audit logs; and the sharing, permission, and download events behind a document-leak claim.
  • Control-plane logs — AWS CloudTrail, Azure activity logs, and Google Cloud audit logs, recording who created, changed, or deleted infrastructure, and which identity assumed which role to do it.
  • Storage, network, and workload artifacts — object-storage access logs, bucket and ACL configuration history, VPC flow logs, EBS and disk snapshots acquired as images, and container or serverless execution logs for workloads that no longer exist.
  • SaaS application audit exports — messaging, file-sharing, CRM, and HR platforms, each with its own export format, its own retention, and its own definition of what counts as an event.

The retention race

The defining constraint is time. High-value records are commonly retained for 30, 90, or 180 days by default; several of the most probative sources — data-plane events, flow logs, storage access logs — are not captured at all unless someone turned them on before the incident; and ephemeral compute disappears when an instance terminates. Preservation therefore precedes analysis: raise retention, export what exists now, snapshot what can be snapshotted, and put the hold in writing. The consequence of arriving late is not a slower investigation, it is a permanently smaller record.

Where this comes up

  • Business email compromise and account-takeover matters, where the dispute is what the intruder reached and for how long
  • Departing-employee and trade-secret claims, where the exfiltration route is a personal cloud account or a share link rather than a USB device
  • Breach-scope and notification disputes, where the number of affected records drives statutory and contractual obligations
  • eDiscovery disputes about the completeness of a collection, the adequacy of search, and whether a source was reasonably accessible
  • Rebuttal work testing whether another expert's cloud collection was complete and whether their queries returned what they claim

How the engagement runs

  1. Conflicts and scope. Parties run for conflicts, then a scoping call to fix the question, the tenants and accounts in play, the deadline, and the role.
  2. Preservation, same day. Written instructions to raise audit retention, enable logging that is off, place holds on mailboxes and drives, snapshot affected workloads, and stop the remediation steps that would destroy the record — password resets and token revocations are necessary, but they should follow the export, not precede it.
  3. Access and authority. The collection account, its permissions, and the authority for the collection are documented before anything is pulled. In most matters the tenant owner executes or authorises the export; the examiner directs and records it.
  4. Collection. Each export records the exact query, parameters, date range and time zone, the API or console used, the account that ran it, the record count returned, and a hash computed on receipt. Provider-supplied integrity values are captured alongside.
  5. Normalisation and correlation. Timestamps are converted to a single reference — most cloud logs are UTC and most endpoint artifacts are not — and identity, application, and infrastructure events are aligned with endpoint and network evidence into one timeline.
  6. Report and testimony. Written opinion with the collection record as an exhibit, and, where the records will be offered at trial, a certification supporting self-authentication.

Getting cloud records admitted

Cloud evidence is challenged on authenticity more often than on substance, because the opposing party cannot inspect the system that produced it. Two rules do most of the work, and both reward decisions made at the moment of collection rather than months later:

A record generated by an electronic process or system that produces an accurate result is self-authenticating on the certification of a qualified person; so is data copied from an electronic device, storage medium, or file, if authenticated by a process of digital identification. In each case the proponent must give the adverse party reasonable written notice and make the record and certification available for inspection.
FED. R. EVID. 902(13)–(14)

A hash taken when the export lands is what makes Rule 902(14) available; a contemporaneous collection record describing the query and the system is what supports Rule 901(b)(9) and a Rule 902(13) certification. Neither can be reconstructed convincingly after the fact, which is the practical argument for involving the examiner before the export rather than after it.

What you receive

DELIVERABLEWHEN IT IS THE RIGHT INSTRUMENT
FRCP 26(a)(2)(B) reportRetained testifying expert in federal court. Opinions and basis, facts or data considered, exhibits, qualifications with a ten-year publication list, four-year testimony list, and compensation.
Declaration under 28 U.S.C. § 1746Preliminary injunction, spoliation motion, motion to compel, or a dispute about the adequacy of a cloud collection.
Rebuttal reportResponding to another expert's cloud analysis. Due within 30 days of that disclosure absent a court order.
FRE 902(13) / 902(14) certificationOffering the exported records themselves at trial without calling a custodian from the provider.
Collection record and hash logProduced with the export in nearly every matter. It is the exhibit that answers 'how do we know this is what the system held'.

How each of these is disclosed, deposed, and defended is set out on the expert witness testimony page.

Questions counsel ask

Can you get the data directly from Microsoft, Google, or AWS?

Generally not in civil litigation, and that surprises people. The Stored Communications Act bars a provider of public electronic communication or remote computing services from divulging the contents of communications, and it contains no exception for a civil subpoena — which is why courts routinely quash subpoenas to providers for message content. The practical route is the tenant: the organisation that holds the account consents to and executes the collection from its own environment, using its own administrative access, and the examiner documents that path. Provider-side process has a real but narrow role, mostly for non-content subscriber records and in criminal or governmental matters.

How far back do cloud logs actually go?

Less far than clients expect, and it varies by platform, log type, and licence tier. Microsoft 365 audit retention commonly runs 90 to 180 days by default with longer windows on higher tiers; Google Workspace retention differs per log type; and in AWS the free CloudTrail event history covers roughly 90 days of management events while data events and VPC flow logs are not captured at all unless someone enabled them first. The first hour of a cloud matter is therefore spent on preservation — raising retention, exporting what exists, and capturing snapshots — not on analysis.

How is a cloud record authenticated for admissibility?

Two routes, usually in combination. Federal Rule of Evidence 901(b)(9) allows authentication by evidence describing a process or system and showing that it produces an accurate result, which is what an examiner's testimony about the export process supplies. Rules 902(13) and 902(14) allow self-authentication of records generated by an electronic process and of data copied from an electronic device or file identified by hash, each on the certification of a qualified person and with advance written notice to the opposing party. Doing the hashing at the moment of export is what makes the second route available months later.

Is a tenant export the same thing as a forensic image?

No, and the report should say so. There is no hardware to write-block and no sector-level copy to hash against a source; what exists is a query run against a provider's system that returns records, and a different query returns a different set. Defensibility comes from documenting the collection account, the exact query parameters and date range, the export format, the provider-supplied integrity values, and a hash computed on receipt — so that the opposing expert can run the same query and compare. That is a different proof from disk imaging, and stating it as equivalent is where cloud opinions get attacked.

Can you tell whether a file was downloaded or only viewed?

Usually yes, because the platforms record those as distinct operations — a preview, an open, a sync, and a download each generate different audit events, and file-sharing changes generate their own. The reliability depends on whether the relevant auditing was enabled and licensed at the time, and on whether the activity happened through a client that reports it. Where the audit record is thin, the endpoint often supplies the corroboration: local sync databases and file system artifacts show what actually landed on a device.

The account was accessed from an unfamiliar country. Does that prove intrusion?

Not on its own. Geolocation of an IP address is an inference from a commercial database that is regularly wrong at the city level, and VPNs, corporate egress points, mobile carrier routing, and cloud relays all displace the apparent origin. A defensible attribution reads the sign-in record together with the authentication method, the token and device identifiers, the user agent, the sequence of events on the account, and any contemporaneous activity on the user's own devices — and states the residual uncertainty rather than resolving it in the retaining party's favour.
ENGAGE A CLOUD FORENSICS EXAMINER

Cloud audit records expire on the provider’s schedule, not yours. Send the matter, the venue, the key dates, and the platforms involved — a conflicts check and a scoping call follow, and preservation instructions can go out the same day.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

Attorney advertising / expert services. This page describes forensic practice and the procedural rules that govern expert evidence in general terms. It is not legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum. Prior results do not guarantee a similar outcome.