Forensic Cloud Service Collector

Spend a lot of time in cloud storage/social media. For cloud storage is fairly easy to obtain the docs via sync or export. The problems are, like email, in the beginning with account setup/access/2FA. A single user interface with provisioning mapped out like in FEC would be a big productivity boost. There are other annoyances like Google Vault outputting Drive docs in one folder and providing XML logs that have to be parsed to match custodian with files…and the fact that Vault is an add-on license.

For social media, X1 was an excellent tool but post-Cambridge Analytica provider API restrictions have really hurt the capture ability. For some providers you can run the risk of the collection account being terminated for abuse by using the tool. For them and other tools there is also the issue of doing a forensically-sound preservation but outputting in a format that doesn’t look like the original website. It’s silly but a big issue with attorneys and others. Continuous scroll websites like Instagram are a great example. Need the images and associated metadata but they also want a good looking continuous screen cap as well. We can get it done but always looking for better mouse traps. Also some providers do a good job but price per capture which is a pain to handle. Self-help tools, even if more expensive, are always preferred.

For chat, Slack would be at the top of the list of requests.

1 Like