602-725-2818Licensed, insured & bondedSchedule a Consultation
Call 602-725-2818Consultation

Digital Forensics

Cloud Account Extraction

Authorized acquisition from over 100 cloud services, merged into a single chronological timeline alongside device evidence.

OxygenPrimary Engine
CellebriteUFED
MagnetVeraKey
Chain of CustodyEvery Engagement
Court-ReadyBy Design

Most of the evidence no longer lives on the device

Backups, synced photos, message archives, document history and location data increasingly sit in cloud accounts rather than on the handset. A device-only examination now misses the majority of the record, and often the most complete part of it.

Cloud acquisition is performed for authorized account holders and merged with device and computer evidence so that the timeline reads as one sequence rather than three disconnected exports.

What we deliver

Multi-Service Acquisition

Extraction across more than 100 cloud services including backup, messaging and storage platforms.

Unified Timeline

Cloud, mobile and computer evidence merged into a single chronological record.

Application Data

Third-party application data parsed rather than left as raw unreadable export.

Account History

Access history, device associations and account activity relevant to attribution.

The evidence has moved to the account

For most organisations the decisive record is no longer on a laptop. It is in a mailbox, a file-sharing tenant, a chat platform and the audit logs that sit behind them. A departing employee who downloads nothing to a company device but forwards to a personal address, shares a folder externally, or syncs to a personal cloud account leaves almost no trace on the machine and a very clear one in the tenant.

Cloud extraction is the discipline of collecting that material defensibly. It is different from device forensics in three ways that matter: the data is controlled by a provider rather than by you, retention is governed by policy and by the platform rather than by physics, and the audit logs — which are frequently the most valuable part — expire on a schedule regardless of what anyone intends.

Which produces the single most important point on this page: preservation is time-critical, and the clock is not yours. Default audit retention on many platforms is measured in months and sometimes less. A litigation hold applied at the tenant preserves mailbox and file content against deletion, but it does not retroactively recover logs that already aged out. Apply holds and preserve logs first; decide what to analyse afterwards.

What is collected

Mail. Messages, attachments, calendar and contacts, including deleted and recoverable items, with the internet headers that establish routing and, frequently, the difference between a genuine message and a spoofed one.

Files and collaboration. Documents with version history, sharing permissions and external sharing links, and the record of who accessed what and when. Version history alone often answers a document-alteration question that would otherwise be unanswerable.

Chat and meetings. Channel and direct messages, shared files, and meeting records where they are retained.

Audit and sign-in logs. The high-value material. Authentication events with location, address and device, consent grants to third-party applications, mailbox rule creation — the classic business email compromise signature is a forwarding rule created quietly and immediately — administrative changes, file access and download volumes, and external sharing events.

Configuration. Mailbox rules and delegate permissions, application consents, multi-factor status and legacy authentication, and conditional access policy — because in an intrusion the attacker’s persistence usually sits in configuration rather than in content.

Authority, and the question of whose account it is

Cloud extraction turns on authorisation more than technique, and this is where engagements are correctly refused.

An organisation’s own tenant — its Microsoft 365 or Google Workspace environment — can be collected under the organisation’s authority, subject to its policies and to employment and privacy considerations for the individual concerned. That is the majority of this work and it is straightforward.

An individual’s personal account can be collected with that individual’s informed authorisation and their credentials, which they provide. It cannot be collected on the authority of a spouse, an employer, a parent of an adult, or anyone in possession of their device.

Where the account holder will not consent, the route is legal process — a subpoena or court order to the provider — and providers respond to properly served process, not to investigators. What we do is establish precisely which provider, which account identifiers, which record types and which period, so the request returns something rather than a formulaic objection.

We do not use credentials found on a device, guess or reset passwords, or use session tokens obtained from someone else’s machine to access an account. Investigative work in Arizona is licensed under A.R.S. Title 32, Chapter 24; Honeybadger holds Private Investigations Agency licence 1759795.

How the collection is done defensibly

Documented authorisation before anything is touched. Scope agreed — custodians, date ranges, data types — because a proportionate collection is both cheaper and far easier to defend than a full tenant export. Preservation holds applied first so nothing changes during the collection. Collection through the platform’s own compliance and export mechanisms wherever possible, because those produce records the provider itself will stand behind. Hash verification of the export. A complete chain of custody. And a contemporaneous record of exactly what was collected, from where, by whom and when — including what was excluded and why.

Analysis then runs against the actual question: reconstructing an intrusion timeline from sign-in and consent events, establishing what a departing employee shared or downloaded, tracing a fraudulent payment instruction through headers and rules, or producing a defensible set for review.

Where the same matter also involves devices, it runs alongside computer forensics and mobile forensics under one file, because the account and the device each hold half of most stories. Where attribution is the objective, it connects to cyber investigations.

How it is priced

Quoted per custodian and per data source, driven by the number of accounts, volume, date range, and whether audit logs and configuration are included. Emergency preservation — applying holds and exporting logs before they expire — is a small, fast engagement we will always recommend doing first and separately.

Included: authorisation review and scoping, preservation, collection through platform mechanisms, hash verification, chain of custody, and a written report. Quoted separately: extended analysis, review platform hosting, additional custodians, and testimony.

Frequently asked questions

An employee left and we think they took data. What is the first step?

Put a hold on their mailbox and files before anything is deleted, and export the audit logs — those expire on the platform’s schedule, not yours. Do not delete or reassign the account. Preservation is cheap and irreversible if skipped; analysis can always follow.

Can you get into someone’s personal email account?

Only with that person’s informed authorisation and credentials, or through legal process served on the provider. Not on a spouse’s authority, not on an employer’s, and not with credentials found on a device. Doing it any other way is a crime and produces evidence nobody can use.

How far back do the logs go?

It depends on the platform and the licence tier, and default retention is often shorter than clients assume — sometimes months, sometimes less. That is why preservation is urgent. Once a log has aged out, no hold applied afterwards brings it back.

We think our email was compromised. What will you find?

Usually the whole shape of it: sign-in events with location and device, the consent grant or legacy authentication used, forwarding or inbox rules created to hide replies, what was accessed, and whether anything was downloaded or shared externally. That analysis is what determines your notification obligations.

Do we have to collect everything?

No, and you should not. A scoped collection — named custodians, defined date ranges, defined data types — is more proportionate, more defensible and much cheaper than a full tenant export. Agreeing scope in advance also avoids the fight about it later.

Will a cloud export hold up in court?

Yes, where it is done through the platform’s own compliance mechanisms with hash verification and a documented chain of custody. Screenshots and forwarded copies will not — they lose the metadata and the provider will not stand behind them.

Who this is for

  • Law firms
  • Corporate counsel
  • HR & compliance
  • Insurers
  • Estate matters
  • Account compromise investigations

Cloud acquisition is performed for authorized account holders only, with written confirmation of authority on file before work begins.

Scope your requirement

Bring the account details, the authorization, and the date range that matters. We will tell you honestly what is likely to be recoverable before you commit to the work.