Cloud Storage Forensics: Endpoint Evidence

  • Tuesday, 03 Dec 2019 3:30PM EST (03 Dec 2019 20:30 UTC)
  • Speaker: Chad Tilbury

An often overlooked area of cloud forensics is data and metadata stored on the local device. 'Unsurprisingly, devices which have synchronized to a cloud storage service may contain a wealth of information relevant to an investigation. Devices regularly record metadata on locally synchronized files in addition to files only present in the cloud. 'Deleted items may still be recoverable, and files may be present in cloud storage cache folders even when they were not selected for local synchronization. 'In short, cloud storage data can be more accessible on the local device and can contain files and metadata distinctly different than the current cloud repository. 'However, endpoint collection includes its own set of challenges. 'In this webcast, SANS Senior Instructor Chad Tilbury will discuss these challenges and provide a strategy for ensuring you are not missing critical evidence in your investigations. '