Canada, BC
(604) 800-9060
TERADRIVEFORENSICS
Glossary

Glossary term

Cloud Forensics

Cloud forensics is the practice of collecting, preserving, and analysing digital evidence from cloud platforms (Microsoft 365, Google Workspace, AWS, Slack, Teams, Salesforce, and others) for litigation, investigation, or regulatory purposes.

Cloud forensics is now central to most workplace investigations. Email, chat, documents, calendars, and audit logs all live in cloud tenants, and the retention windows are short.

The process begins with tenant-level scoping: confirming the platforms, custodians, date range, and data types within scope, plus the tenant configuration that determines what is recoverable. M365 unified audit log retention is 90 to 180 days by default. Google Workspace varies by event type. Slack retention depends on workspace plan.

Collection is performed through the platform's native eDiscovery tooling (Microsoft Purview, Google Vault) and supplemented with API-based collection (often via Magnet AXIOM Cyber) where needed.

Analysis reconstructs user activity timelines, identifies exfiltration patterns, and surfaces anomalous administrative actions. The deliverable ties findings to specific audit-log entries.

For Canadian counsel, cloud forensics often replaces or supplements traditional endpoint forensics. The audit log lives outside the user's control and is harder to challenge than user-side artifacts.

Related terms

Need digital evidence handled defensibly?

Book a confidential consultation. Our team will reach out as soon as possible.