Webinar: Collect and Review Cloud Artifacts with Belkasoft
Cloud forensics is the application of digital forensics to cloud environments. Using a hybrid approach that taps into the devices and credentials used to access cloud services, it reconstructs past cloud computing events through the identification, acquisition, preservation, examination, and reporting of digital evidence. This webinar will address the challenges investigators encounter with cloud data and demonstrate how to acquire and analyze artifacts from Google Cloud, iCloud, Microsoft Office 365, and other services using Belkasoft X.
Which cloud services can be acquired
Belkasoft X acquires and analyzes data from a wide range of cloud services:
- Google Cloud—Drive, Gmail, Keep, Timeline, Sync, and My Activity
- iCloud and iCloud backups—including device backups and data from all linked devices
- Microsoft Office 365
- Messaging—WhatsApp (including via QR code) and Instagram
- Email—more than 25 webmail services, including Yahoo, Hotmail, and Opera
- Cloud storage—Carbonite
Key capabilities shown in the webinar
- iCloud data can be acquired without physical access to the device
- Backups of all linked devices can be acquired through a single trusted device bound to the account
- iCloud backups can be downloaded for accounts protected with two-factor authentication, with no email notification sent to the account holder
- Multiple backup snapshots can be compared to see what changed between them
- Deleted chat records can be recovered from SQLite freelists
- Acquired data is analyzed automatically for more than 1,500 artifact types
The challenges of cloud forensics
According to a NIST report, cloud forensics faces 65 challenges grouped into nine categories: architecture, data collection, analysis, anti-forensics, incident first response, role management, legal, standards, and training. These challenges exist because cloud data is not stored on a physical drive the investigator controls—acquisition must happen remotely, often across jurisdictions and shared multi-tenant infrastructure.
Presented by
Elena Mishkareva, Digital Forensics Specialist, with a demonstration by Jared Luebbert, forensic sales engineer at Belkasoft.
Who should watch
Digital forensic investigators, corporate incident response teams, and law enforcement dealing with evidence stored in cloud services.
FAQ
What is cloud forensics?
Cloud forensics is the application of digital forensics to cloud environments. Because data is not stored on a physical drive that the investigator controls, it uses a hybrid approach that accesses cloud services through the devices and credentials used to reach them.
Can you acquire iCloud data without the physical device?
Yes. With access to a single trusted device bound to an iCloud account, an investigator can acquire data and backups of all linked devices, including accounts protected with two-factor authentication.
Will the account owner be notified during cloud acquisition?
It depends on what is acquired. Downloading iCloud backups sends no email notification to the account holder, while downloading iCloud application data triggers a notification from Apple.
What cloud services can Belkasoft X acquire?
Google Cloud (Drive, Gmail, Keep, Timeline, Sync, My Activity), iCloud and iCloud backups, Microsoft Office 365, WhatsApp, Instagram, Carbonite, and more than 25 webmail services.
Can deleted cloud data be recovered?
In some cases, yes. Records marked for deletion can remain in a SQLite free list and be recovered during analysis.