Forensic Cloud Service Collector

Hi Arman - from my perspective, cloud storage is definitely a need. There are a couple of tools out there that do a decent job but they all seem to lack completeness for the Business versions of the products outlined above. I think it is important for the data to be downloaded into some sort of container rather than sitting loosely on a file system. In addition (since I work for an eDiscovery service provider) its important for the data to be extracted out to a windows file system while preserving the metadata for processing into eDiscovery tools.

More and more we are seeing Slack come into play from a collection standpoint and would love to have the ability to collect the data in a format that can play nicely with data processing or review tools. I also think anything you can do in the social media space would be helpful. That market is so volatile it is great to have several trusted tools in our forensic tool box to collect and verify work that is done.

For me, one of the biggest headaches when dealing with cloud data sources (both storage and social media) is related to authentication. Some services require 2FA to be enabled to access using third party applications. Other services require using an application password. Some tools only allow you to access the data if 2FA is turned off. And on top of all of that, we often run into the “this device is not recognized” prompts even when we think its not going to require additional security verification. This often frustrates custodians and lawyers and that is why we love the token for FEC! We just need a version for Mac OS :smiley:. Anything you can do to make the authentication piece easier for the end user will greatly be appreciated!

2 Likes