Book online or chat with usAnswered 24/7Licensed, insured & bondedSchedule a Consultation
Request serviceUrgentConsultation

Digital Forensics

Cloud Account Extraction

Authorized acquisition from over 100 cloud services, merged into a single chronological timeline alongside device evidence.

OxygenPrimary Engine
CellebriteUFED
MagnetVeraKey
Chain of CustodyEvery Engagement
Court-ReadyBy Design

Most of the evidence no longer lives on the device

Backups, synced photos, message archives, document history and location data increasingly sit in cloud accounts rather than on the handset. A device-only examination now misses the majority of the record, and often the most complete part of it.

Cloud acquisition is performed for authorized account holders and merged with device and computer evidence so that the timeline reads as one sequence rather than three disconnected exports.

What we deliver

Multi-Service Acquisition

Extraction across more than 100 cloud services including backup, messaging and storage platforms.

Unified Timeline

Cloud, mobile and computer evidence merged into a single chronological record.

Application Data

Third-party application data parsed rather than left as raw unreadable export.

Account History

Access history, device associations and account activity relevant to attribution.

The evidence has moved to the account

For most organisations the decisive record is no longer on a laptop. It is in a mailbox, a file-sharing tenant, a chat platform and the audit logs that sit behind them. A departing employee who downloads nothing to a company device but forwards to a personal address, shares a folder externally, or syncs to a personal cloud account leaves almost no trace on the machine and a very clear one in the tenant.

Cloud extraction is the discipline of collecting that material defensibly. It is different from device forensics in three ways that matter: the data is controlled by a provider rather than by you, retention is governed by policy and by the platform rather than by physics, and the audit logs — which are frequently the most valuable part — expire on a schedule regardless of what anyone intends.

Which produces the single most important point on this page: preservation is time-critical, and the clock is not yours. Default audit retention on many platforms is measured in months and sometimes less. A litigation hold applied at the tenant preserves mailbox and file content against deletion, but it does not retroactively recover logs that already aged out. Apply holds and preserve logs first; decide what to analyse afterwards.

What is collected

Mail. Messages, attachments, calendar and contacts, including deleted and recoverable items, with the internet headers that establish routing and, frequently, the difference between a genuine message and a spoofed one.

Files and collaboration. Documents with version history, sharing permissions and external sharing links, and the record of who accessed what and when. Version history alone often answers a document-alteration question that would otherwise be unanswerable.

Chat and meetings. Channel and direct messages, shared files, and meeting records where they are retained.

Audit and sign-in logs. The high-value material. Authentication events with location, address and device, consent grants to third-party applications, mailbox rule creation — the classic business email compromise signature is a forwarding rule created quietly and immediately — administrative changes, file access and download volumes, and external sharing events.

Configuration. Mailbox rules and delegate permissions, application consents, multi-factor status and legacy authentication, and conditional access policy — because in an intrusion the attacker’s persistence usually sits in configuration rather than in content.

Authority, and the question of whose account it is

Cloud extraction turns on authorisation more than technique, and this is where engagements are correctly refused.

An organisation’s own tenant — its Microsoft 365 or Google Workspace environment — can be collected under the organisation’s authority, subject to its policies and to employment and privacy considerations for the individual concerned. That is the majority of this work and it is straightforward.

An individual’s personal account can be collected with that individual’s informed authorisation and their credentials, which they provide. It cannot be collected on the authority of a spouse, an employer, a parent of an adult, or anyone in possession of their device.

Where the account holder will not consent, the route is legal process — a subpoena or court order to the provider — and providers respond to properly served process, not to investigators. What we do is establish precisely which provider, which account identifiers, which record types and which period, so the request returns something rather than a formulaic objection.

We do not use credentials found on a device, guess or reset passwords, or use session tokens obtained from someone else’s machine to access an account. Investigative work in Arizona is licensed under A.R.S. Title 32, Chapter 24; Honeybadger holds Private Investigations Agency licence 1759795.

How the collection is done defensibly

Documented authorisation before anything is touched. Scope agreed — custodians, date ranges, data types — because a proportionate collection is both cheaper and far easier to defend than a full tenant export. Preservation holds applied first so nothing changes during the collection. Collection through the platform’s own compliance and export mechanisms wherever possible, because those produce records the provider itself will stand behind. Hash verification of the export. A complete chain of custody. And a contemporaneous record of exactly what was collected, from where, by whom and when — including what was excluded and why.

Analysis then runs against the actual question: reconstructing an intrusion timeline from sign-in and consent events, establishing what a departing employee shared or downloaded, tracing a fraudulent payment instruction through headers and rules, or producing a defensible set for review.

Where the same matter also involves devices, it runs alongside computer forensics and mobile forensics under one file, because the account and the device each hold half of most stories. Where attribution is the objective, it connects to cyber investigations.

How it is priced

Quoted per custodian and per data source, driven by the number of accounts, volume, date range, and whether audit logs and configuration are included. Emergency preservation — applying holds and exporting logs before they expire — is a small, fast engagement we will always recommend doing first and separately.

Included: authorisation review and scoping, preservation, collection through platform mechanisms, hash verification, chain of custody, and a written report. Quoted separately: extended analysis, review platform hosting, additional custodians, and testimony.

Frequently asked questions

An employee left and we think they took data. What is the first step?

Put a hold on their mailbox and files before anything is deleted, and export the audit logs — those expire on the platform’s schedule, not yours. Do not delete or reassign the account. Preservation is cheap and irreversible if skipped; analysis can always follow.

Can you get into someone’s personal email account?

Only with that person’s informed authorisation and credentials, or through legal process served on the provider. Not on a spouse’s authority, not on an employer’s, and not with credentials found on a device. Doing it any other way is a crime and produces evidence nobody can use.

How far back do the logs go?

It depends on the platform and the licence tier, and default retention is often shorter than clients assume — sometimes months, sometimes less. That is why preservation is urgent. Once a log has aged out, no hold applied afterwards brings it back.

We think our email was compromised. What will you find?

Usually the whole shape of it: sign-in events with location and device, the consent grant or legacy authentication used, forwarding or inbox rules created to hide replies, what was accessed, and whether anything was downloaded or shared externally. That analysis is what determines your notification obligations.

Do we have to collect everything?

No, and you should not. A scoped collection — named custodians, defined date ranges, defined data types — is more proportionate, more defensible and much cheaper than a full tenant export. Agreeing scope in advance also avoids the fight about it later.

Will a cloud export hold up in court?

Yes, where it is done through the platform’s own compliance mechanisms with hash verification and a documented chain of custody. Screenshots and forwarded copies will not — they lose the metadata and the provider will not stand behind them.

Who this is for

  • Law firms
  • Corporate counsel
  • HR & compliance
  • Insurers
  • Estate matters
  • Account compromise investigations

Cloud acquisition is performed for authorized account holders only, with written confirmation of authority on file before work begins.

Guides on this topic

Scope your requirement

Bring the account details, the authorization, and the date range that matters. We will tell you honestly what is likely to be recoverable before you commit to the work.

Avoidable damage

Mistakes that weaken cloud evidence before we arrive

Well-intended first responses inside an organization can erase or muddy the record. Most of these are easy to avoid once you know about them.

Deleting the malicious rule first

Removing a forwarding or inbox rule stops the harm, but it should be documented and the logs exported before or alongside that change so the evidence of when and how it was created is kept.

Removing the user’s license or account

On some platforms, unlicensing or deleting a departed user starts a countdown after which mailbox and file data may be removed. Suspend access instead and keep the data intact until it is preserved.

Browsing the account to look around

Signing in as the user or opening files from an administrator account adds new activity to the logs and can blur the timeline you are trying to reconstruct.

Forwarding messages as evidence

A forwarded email or a screenshot strips headers and metadata. Leave originals in place and preserve them through the platform’s own tools.

Uncoordinated containment

Password resets and session revocation are often necessary. Record what was done, by whom and when, so the analysis can separate your actions from the attacker’s.

Our page on forensic data preservation and legal holds explains how holds fit into a broader preservation plan, and the business email compromise response guide covers the first hours of a mailbox intrusion.

Before the first call

What to gather so scoping is fast

These details let us confirm authority, plan preservation and estimate effort in a single conversation.

  1. Platform and subscription. Identify the service in use and, where you know it, the subscription or license tier, since that affects which logs exist and how long they are retained.
  2. Administrator contact. Name the person who can grant access, apply holds and approve exports, whether internal IT or a managed provider.
  3. Custodians and accounts. List the people and account identifiers involved, including shared mailboxes and service accounts.
  4. Key dates. Note when the suspected activity began, when it was discovered and any departure or termination date.
  5. Actions already taken. Record any password resets, rule deletions, license changes or holds so far, with approximate times.
  6. Written authority. Prepare documentation showing who authorizes the collection, whether that is an officer of the organization or the account holder.

For departures specifically, see our guide to departing employee data theft investigations.

Estate matters

Accounts of a deceased or incapacitated person

Families and fiduciaries often need access to photos, documents or financial records held in a loved one’s cloud account. The path is different from a corporate collection.

Major providers maintain their own processes for accounts of deceased users, and some let account holders name a legacy or inactive-account contact in advance. Providers typically ask for documentation such as a death certificate and proof of legal authority, and what they release varies by provider and circumstance.

Where access is granted, we can collect and preserve the material defensibly so it is usable in probate or a dispute among heirs. Where it is not, we can help counsel identify precisely which account and records to request. Requirements differ by provider and jurisdiction; confirm with estate counsel. This is not legal advice.

To discuss a collection, whether corporate or personal, start with a confidential consultation.