Page 1
CLOUDEXFILTRATION · A GUIDE FOR UK LAWYERS Data Exfiltration to Cloud Storage Tracing Company Data Uploaded to Personal and Third-Party Clouds COMPUTER FORENSICS LAB
§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM ESTABLISHED 2007 · LONDON ISO 17025-ALIGNED PROCEDURES CLOUD-EXFILTRATION INVESTIGATION SYNC-CLIENT & EGRESS ANALYSIS CPR PART 35 EXPERT REPORT S FULL CHAIN-OF-CUSTODY DOCUMENTATION
§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: the network copy that writes to both ends 03 The routes: sync clients, browser uploads, sharing, webmail and rules 04 The end point record: sync databases, browser artefacts and local traces 05 The platform and network record: audit logs, sharing events and egress 06 The destination: reaching the personal cloud account through process 07 Quantification, deployment and the innocent explanation 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist
§ 01 · ORIENTATION Executive summary THE HEADLINE POINT: CLOUDEXFILTRATIONWRITESTOTHEENDPOINT, THE CORPORATE PLATFORM, THENETWORKANDTHEDESTINATIONACCOUNT: PROVEWHAT LEFTFROMTHEFIRSTTHREE, REACHWHEREITWENTTHROUGHTHEFOURTH, AND QUANTIFYTOAFILE - LEVELMANIFEST
§ 02 · FIRST PRINCIPLES The problem in plain English: the network copy that writes to both ends
§ 03 · THEROUTES The routes: sync clients, browser uploads, sharing, webmail and rules
Page 2
§ 04 · THEENDPOINTRECORD The end point record: sync databases, browser artefacts and local traces
§ 05 · THEPLATFORMANDNETWORKRECORD The platform and network record: audit logs, sharing events and egress
§ 06 · THEDESTINATION The destination: reaching the personal cloud account through process 97
§ 7): what arrived, who accessed it, and its quarantine and return: the receiving side of the transfer.
§ 07 · QUANTIFICATIONANDDEPLOYMENT Quantification, deployment and the innocent explanation
§ 08 · THEWIDERMAP Source architecture: where else the evidence lives QUESTION PLATFORM ACCOUNT + EMPLOYER ORIGINATING EGRESS BEHAVIOURAL END POINT (PROXY/ LAYER CORPORATE DESTINATION NEW AUDIT PROVIDER ESTATE NETWORK DLP/CASB)
Page 3
§ 09 · IN THE WILD Worked examples EXAMPLE1 · THEPERSONALDRIVETHATMIRROREDTHEWHOLEDESK EXAMPLE2 · THEFOLDERTHATWASSHARED, NOTDOWNLOADED EXAMPLE3 · THESYNCTHATWASSANCTIONED, ANDTHECLAIMTHATNARROWED
§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations
§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent (the former employee / new employer) Ask your e Discovery / forensic provider ( FIRST LETTER )
§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The cloud-exfiltration checklist Red flags When to involve a digital forensic expert
§ 13 · COMMON QUESTIONS Frequently asked questions The data went to a personal cloud account. Can we even prove it? The employee just shared a folder rather than downloading anything. Is that exfiltration? Can we get into the employee's personal cloud account? The employee had a sanctioned personal cloud for home-working. Does that defeat the claim? How fast do we need to move? Does the employer have its own obligations if client personal data left?
§ 14 · REFERENCE Glossary CASB DLP Sources and authoritative references DISCLAIMER
Page 4
§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY
Cite as: Joseph Naghdi, Data Exfiltration To Cloud Storage, Computer Forensics Lab, https://e-discovery.uk/library/data-exfiltration-to-cloud-storage/pdf.
