Files, account access and sharing activity
Cloud & SaaS Forensics
Who accessed a shared folder, downloaded business records or sent a document outside the company? GDF preserves cloud files and activity logs, connects the events and explains the findings.
Connect the application to the evidence
Joseph Caruso's background includes databases, transactional systems, source code and cybersecurity incident response. That experience helps counsel examine how the underlying system produced the records at issue.
Follow the information across connected accounts
Business records can move between shared folders, email, messaging tools and local computers. A cloud forensic examination connects the original files, their versions, permissions and activity records to the people and dates in your matter.
GDF works with counsel, security teams and authorized administrators to identify the relevant accounts and applications. We preserve the records, correlate activity and prepare findings for employee departures, commercial disputes, compromised accounts and discovery.
Files and logs serve different purposes
The document shows its contents. Version history can show how it changed. Sharing records describe access permissions, while activity logs may record downloads, synchronization, administrative changes and account sign-ins. Together, these sources support a more complete explanation of the event.
We identify the original file, owner, account, relevant versions and surrounding activity. Each finding is tied to the records that establish it. Early collection preserves the evidence around account closure, staff changes and routine record retention.
Discuss your cloud accounts and evidence
Tell us which files, accounts or access changes are in question. We can plan collection of the records that explain who accessed, shared or changed company information.
Microsoft 365, Google Workspace and business applications
- Microsoft 365: Outlook email, OneDrive and SharePoint documents, sharing and account activity.
- Google Workspace: Gmail, Google Drive files, permissions and Workspace logs.
- Collaboration applications: relevant Slack, Teams, Box and Dropbox records, linked documents and communications.
- Cloud infrastructure: authorized AWS and Azure records, object storage and identity activity within the examination scope.
We review the available export and logging options for each source, then document collection methods, dates and handling.
Remote collection coordinated with your team
Tell us which applications hold the information and who administers them. We arrange authorized access, identify the relevant accounts and date ranges, and coordinate collection with your IT team. Users can continue using their email accounts during routine remote collection.
Collected files, activity logs and source records are preserved with integrity checks and chain-of-custody documentation. Computer or mobile evidence can be added when it helps explain local downloads, chats or file movement.
Employee departures and compromised accounts
A departure review may connect a shared-folder download, an email attachment and a USB connection on the employee's computer. A compromised-account examination may connect a suspicious sign-in, a forwarding rule and subsequent file access. These are examples of questions that guide collection and analysis.
Employee exit Core Analysis offers a flat-rate examination for an agreed scope. Explore executive departures, partner separations or business email takeover analysis for those specific needs.
A report counsel and business leaders can use
Deliverables can include an evidence inventory, account and file-access timeline, sharing analysis and relevant exhibits. We explain the account identifiers, timestamps and source records in plain language.
For litigation, connect the examination with discovery review and production and expert reports and testimony. Our national computer, email and cloud guide explains the wider examination.
Evidence reviewed
- Authorized accounts, files and messages within scope
- Relevant activity logs and supporting device records
- Collection and chain-of-custody documentation
What you receive
- Evidence inventory and documented findings
- Activity timelines and relevant exhibits
- Review-ready material, reports and expert support
Frequently asked
Common questions
Can you establish who downloaded or shared a cloud file?
GDF examines file activity, sharing records, account identifiers and sign-in evidence to establish the recorded access and transfers. We connect those findings to relevant computer, email and application records.
Do you collect Google Drive and OneDrive files?
Yes. We collect authorized Google Drive, OneDrive and SharePoint sources, together with relevant file information, versions and available activity logs.
Can you review external sharing after an employee leaves?
Yes. We examine sharing permissions, file movement and communication around the departure. The resulting timeline helps counsel and business leaders understand how company information was handled.
What should we preserve first?
Discuss the affected accounts, files and dates with GDF. We identify relevant activity logs, original documents, version history and connected devices, then coordinate preservation with the authorized administrator.
Can you provide discovery production and testimony?
Yes. The examination can include data prepared for review, agreed production formats, a forensic report and expert testimony. We plan those deliverables with counsel at the start.
Find the cloud activity that matters
Find regional collection and engagement information or meet the forensic team. Ask about the collection method and report format that fit your matter.
Discuss your cloud accounts and evidence
Call to discuss your next step and arrange secure information sharing.