WhatsApp
Cloud forensics · Acquisition & analysis of cloud artefacts

The evidence isn't on the device any more. It's in the cloud.

Cloud forensics: sources of cloud evidence — mail, documents, communications, share/export logs and system logs — collected under chain of custody.

Most matters that reach a solicitor's desk today turn on records that never lived on a single hard drive: a document edited in SharePoint, a file shared out of a personal Dropbox on a Friday evening, a Slack thread, a Teams call log, an email that "no longer exists" in either party's mailbox. We acquire and examine those records lawfully, preserve them to evidential standards, and report them so a court can rely on them.

Cloud evidence behaves differently from device evidence. It sits in the custody of a third-party provider, it changes as people keep working, retention windows close on a schedule nobody in the case controls, and access itself leaves traces. Acquisition therefore has to be planned, the right legal basis, the right API or export route, and hash-verified preservation before anything else is touched.

§ 01 · Platforms we examine

Every cloud space a legal team is likely to encounter.

01

Microsoft 365 · OneDrive · Purview

Exchange Online mailboxes, SharePoint and OneDrive document libraries, Teams chats, channels and call records. We work with Purview eDiscovery holds, content searches and audit-log exports, and where a tenant's own tooling isn't enough, with direct API acquisition. Unified audit logs answer the questions tenants can't: who accessed what, from which IP, on which device, and what left the organisation.
02

Google Workspace · Google Drive

Gmail, Drive and shared drives, Docs revision histories, Meet records and Chat spaces, acquired through Vault exports, Takeout preservation or admin-console API access. Drive's revision and activity records are frequently the decisive artefact: they show a document's full editing history, every share event, and every download, long after the file itself has been "deleted".
03

Email forensics, Outlook 365 & Gmail

Authenticating disputed emails from full headers, transport logs and DKIM signatures; recovering purged and double-deleted items from retention stores; tracing mailbox rules, delegate access and sign-in records in account-compromise and payment-fraud matters; and establishing whether a message was actually sent, received, read, or fabricated after the fact.
04

Slack · Box · Dropbox

Workspace exports and Discovery API acquisition for Slack, including private channels and DMs where the plan and legal basis permit. For Box and Dropbox: file event streams, share-link histories, device sync records and deleted-file retention. Sync clients also leave rich artefacts on local machines, letting us tie a cloud event to a specific person at a specific keyboard.
05

Social media & messaging platforms

Preservation and analysis of account data from Facebook, Instagram, X, TikTok, LinkedIn and messaging platforms' cloud backups, via subject-access exports, in-app download tools and, where proceedings justify it, provider disclosure requests. Captured with timestamps and metadata intact, not as screenshots.
06

Backups, VMs & infrastructure

iCloud and Google device backups, AWS and Azure virtual machines and storage buckets, SaaS CRM and accounting platforms. If a client's data lives in it and a court needs it, we will find a defensible route to acquire it.
§ 02 · Method

Defensible acquisition, from legal basis to exhibit.

There is no write-blocker for the cloud. Defensibility comes from process: authority to access, preservation before examination, logged and hash-verified collection, and a custody record covering every step.

Four-stage cloud forensics method: Authority, Preservation, Acquisition, Report.
01

Authority

Consent, employer ownership, court order or provider disclosure, the lawful basis is established and documented before any account is touched.

02

Preservation

Litigation holds, retention locks and immediate exports, stopping the clock on rotation, expiry and deliberate deletion.

03

Acquisition

API-based collection with every request logged, exports hash-verified on receipt, and scope kept proportionate to the issues.

04

Analysis & report

Timeline reconstruction across platforms, correlated with device artefacts, reported to CPR 35 / CrimPR 19 standards.

§ 04 · Why timing is critical

Cloud evidence expires on a schedule no one in your case controls.

Audit logs are kept for fixed windows, often 90 or 180 days on standard licences. Deleted mailbox items purge on a timer. Departed employees' accounts are routinely wiped after offboarding. A preservation request made this week can capture what a court order obtained in six months cannot. If cloud data may matter to a current or anticipated matter, the correct time to preserve it is now.

Sources

Cloud evidence in your matter? Speak to an examiner.