Deutsch

Digital Forensics

Cloud Forensics

Classic forensics starts with an image of the hard disk. In the cloud that disk does not exist — and the logs that take its place disappear after a retention period set by the provider. Cloud forensics is therefore above all a race against time.

Long rows of glowing records recede into darkness. The nearest ones are dissolving; a few in the middle still glow at full strength.
01

The time pressure

Why speed matters

Retention periods for logs differ by provider, plan and log type, and some are short. Some of the most informative data is only available in higher licence tiers and cannot be generated retroactively. Anyone who waits three weeks after a suspicion may already have lost the decisive source. So our first step is always preservation, not analysis.

The scope

What we examine

  1. 01

    Identity

    sign-ins, failed attempts, factor resets, newly granted permissions

  2. 02

    Mailboxes

    forwarding rules, delegations, third-party access, deleted items

  3. 03

    File storage

    bulk downloads, external sharing, version histories

  4. 04

    Infrastructure

    newly created resources, changed network rules, retrieved secrets

  5. 05

    Configuration

    deviations from the documented target state

02

The sequence

The most common pattern

In the majority of cases it does not start with malware but with a taken-over account — through phishing, reused passwords or bypassing the second factor. What follows is almost always the same: an inconspicuous forwarding rule in the mailbox, the creation of a second way in as a fallback, then the actual access. How well your workforce holds up against the first step is what a Social Engineering Assessment tests.

03

The boundary

Shared responsibility

The provider secures the platform, you secure your configuration and your identities. Most of the incidents we investigate arise on the second side of that boundary. Where there is no target state to check against, we establish one with Sightadel — the control catalogues of NIS2, DORA, ISO 27001 and the GDPR are already held there.

04

The follow-through

Afterwards

Every investigation produces a list of changes that prevent a repeat. Ongoing monitoring then runs through SOC as a Service; detecting new anomalies is handled by AI threat detection.

FAQ

Frequently asked questions

What should we do while you are not there yet?

Two things, immediately: raise logging to the highest level available, and start exporting the logs you already have. Both cost nothing and cannot be done retroactively. Delete nothing, change no rules, and do not hastily disable the suspicious account — a disabled account warns the attacker before you know what they did.

Can you investigate if we do not have a higher licence tier?

Yes, but on a narrower basis. Some of the most informative logs are tied to higher tiers and cannot be generated retroactively. We tell you at the outset which questions your licence scope can answer and which stay open — rather than selling you a gap as a result at the end.

Is the provider not responsible for security anyway?

For the platform, yes. For your configuration, your permissions and your identities, no. Practically every incident we investigate arises on your side of that boundary — usually through a taken-over account. The provider supplies the logs; the assessment is yours to make.

Will the provider give you the data you need?

Whatever is reachable through the usual interfaces we collect ourselves. Requests to the provider beyond that take time and do not always succeed. So we plan the investigation to work with the data you can reach yourself.

How does this differ from an investigation in our own datacentre?

There is no storage medium to image and no memory to capture. In their place are logs that belong to somebody else and disappear on somebody else's schedule. So the order reverses: preserve first, then ask what should be investigated.

Digital Forensics

More in this area

Malware Analysis

We take malware apart in an isolated environment and deliver concrete detection rules for your systems rather than a la…

View

Network Forensics

Network traffic reveals what has long been deleted on endpoints. We reconstruct entry, lateral movement and exfiltratio…

View

Mobile Forensics

Company phones often hold more business secrets than any computer. We secure and examine them to an evidentiary standar…

View

Behavioural Forensics

Tools change, habits persist. We analyse how an attacker operates and derive where they will start next time.

View

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.