What it does. Perform forensic acquisition of cloud storage services including Google Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-cloud-storage-forensic-acquisition, or copy the skill folder into ~/.claude/skills/performing-cloud-storage-forensic-acquisition/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/performing-cloud-storage-forensic-acquisition/SKILL.md
SKILL.md (verbatim)
name: performing-cloud-storage-forensic-acquisition
description: Perform forensic acquisition of cloud storage services including Google
Drive, OneDrive, Dropbox, and Box by pulling API-based remote data such as revision
history and audit logs, and collecting local sync-client artifacts including KAPE
targets and OneDrive databases from endpoints. Use during incident response or e-discovery
when evidence resides in cloud-synced storage and both cloud-side and endpoint-side
artifacts must be preserved.
domain: cybersecurity
subdomain: digital-forensics
tags:
- cloud-forensics
- google-drive
- onedrive
- dropbox
- box
- cloud-acquisition
- api-forensics
- sync-client
- endpoint-artifacts
- magnet-axiom
version: '1.0'
author: mahipal
license: Apache-2.0
nist_ai_rmf:
- MEASURE-2.7
- MAP-5.1
- MANAGE-2.4
atlas_techniques:
- AML.T0070
- AML.T0066
- AML.T0082
nist_csf:
- RS.AN-03
- DE.AE-02
- RS.MA-01
mitre_attack:
- T1005
- T1074
- T1119
- T1070
- T1059
Performing Cloud Storage Forensic Acquisition
Overview
Cloud storage forensic acquisition involves collecting digital evidence from services like Google Drive, OneDrive, Dropbox, and Box through both API-based remote acquisition and local endpoint artifact analysis. Modern investigations must address the challenge that cloud-synced files may exist in multiple states: locally synchronized, cloud-only (on-demand), cached, and deleted. Endpoint devices that have synchronized with cloud storage contain a wealth of metadata about locally synced files, files present only in the cloud, and even deleted items recoverable from cache folders. API-based acquisition using service-specific APIs provides direct access to remote data with valid credentials and proper legal authorization.
When to Use
- When conducting security assessments that involve performing cloud storage forensic acquisition
- When following incident response procedures for related security events
- When performing scheduled security testing or auditing activities
- When validating security controls through hands-on testing
Prerequisites
- Legal authorization (warrant, consent, or corporate policy) for cloud data access
- Valid user credentials or administrative access tokens
- Magnet AXIOM Cloud, Cellebrite Cloud Analyzer, or equivalent tool
- KAPE with cloud storage target files
- Python 3.8+ with google-api-python-client, msal, dropbox SDK
- Network connectivity for API-based acquisition
Acquisition Methods
Method 1: API-Based Remote Acquisition
Google Drive API Acquisition
from google.oauth2.credentials import Credentials
from googleapiclient.discovery import build
from googleapiclient.http import MediaIoBaseDownload
import io
import os
import json
from datetime import datetime
class GoogleDriveForensicAcquisition:
"""Forensically acquire files and metadata from Google Drive via API."""
def __init__(self, credentials_path: str, output_dir: str):
self.creds = Credentials.from_authorized_user_file(credentials_path)
self.service = build("drive", "v3", credentials=self.creds)
self.output_dir = output_dir
os.makedirs(output_dir, exist_ok=True)
self.acquisition_log = []
def list_all_files(self, include_trashed: bool = True) -> list:
"""List all files including trashed items."""
files = []
page_token = None
query = "" if include_trashed else "trashed = false"
while True:
results = self.service.files().list(
q=query,
pageSize=1000,
fields="nextPageToken, files(id, name, mimeType, size, "
"createdTime, modifiedTime, trashed, trashedTime, "
"owners, sharingUser, permissions, md5Checksum, "
"parents, webViewLink, driveId)",
pageToken=page_token
).execute()
files.extend(results.get("files", []))
page_token = results.get("nextPageToken")
if not page_token:
break
return files
def download_file(self, file_id: str, file_name: str, mime_type: str) -> str:
"""Download a file from Google Drive preserving forensic integrity."""
output_path = os.path.join(self.output_dir, file_name)
if mime_type.startswith("application/vnd.google-apps"):
export_formats = {
"application/vnd.google-apps.document": "application/pdf",
"application/vnd.google-apps.spreadsheet": "application/vnd.openxmlformats-officedocument.spreadsheetml.sheet",
"application/vnd.google-apps.presentation": "application/pdf",
}
export_mime = export_formats.get(mime_type, "application/pdf")
request = self.service.files().export_media(fileId=file_id, mimeType=export_mime)
else:
request = self.service.files().get_media(fileId=file_id)
with io.FileIO(output_path, "wb") as fh:
downloader = MediaIoBaseDownload(fh, request)
done = False
while not done:
_, done = downloader.next_chunk()
self.acquisition_log.append({
"timestamp": datetime.utcnow().isoformat(),
"file_id": file_id,
"file_name": file_name,
"output_path": output_path,
"action": "downloaded"
})
return output_path
def get_activity_log(self, file_id: str) -> list:
"""Retrieve activity/revision history for a specific file."""
revisions = self.service.revisions().list(
fileId=file_id,
fields="revisions(id, modifiedTime, lastModifyingUser, size, md5Checksum)"
).execute()
return revisions.get("revisions", [])
def export_acquisition_report(self) -> str:
"""Export acquisition log for chain of custody documentation."""
report_path = os.path.join(self.output_dir, "acquisition_log.json")
with open(report_path, "w") as f:
json.dump({
"acquisition_start": self.acquisition_log[0]["timestamp"] if self.acquisition_log else None,
"acquisition_end": datetime.utcnow().isoformat(),
"total_files": len(self.acquisition_log),
"entries": self.acquisition_log
}, f, indent=2)
return report_path
OneDrive / Microsoft 365 API Acquisition
import msal
import requests
import os
import json
from datetime import datetime
class OneDriveForensicAcquisition:
"""Forensically acquire files and metadata from OneDrive via Microsoft Graph API."""
def __init__(self, client_id: str, tenant_id: str, client_secret: str, output_dir: str):
self.output_dir = output_dir
os.makedirs(output_dir, exist_ok=True)
authority = f"https://login.microsoftonline.com/{tenant_id}"
self.app = msal.ConfidentialClientApplication(
client_id, authority=authority, client_credential=client_secret
)
token_result = self.app.acquire_token_for_client(
scopes=["https://graph.microsoft.com/.default"]
)
self.access_token = token_result.get("access_token")
self.headers = {"Authorization": f"Bearer {self.access_token}"}
self.base_url = "https://graph.microsoft.com/v1.0"
def list_user_files(self, user_id: str) -> list:
"""List all files in user's OneDrive."""
url = f"{self.base_url}/users/{user_id}/drive/root/children"
files = []
while url:
response = requests.get(url, headers=self.headers)
data = response.json()
files.extend(data.get("value", []))
url = data.get("@odata.nextLink")
return files
def download_file(self, user_id: str, item_id: str, filename: str) -> str:
"""Download a file from OneDrive."""
url = f"{self.base_url}/users/{user_id}/drive/items/{item_id}/content"
response = requests.get(url, headers=self.headers, stream=True)
output_path = os.path.join(self.output_dir, filename)
with open(output_path, "wb") as f:
for chunk in response.iter_content(chunk_size=8192):
f.write(chunk)
return output_path
def get_deleted_items(self, user_id: str) -> list:
"""Retrieve items from OneDrive recycle bin."""
url = f"{self.base_url}/users/{user_id}/drive/special/recyclebin/children"
response = requests.get(url, headers=self.headers)
return response.json().get("value", [])
Method 2: Local Endpoint Artifact Collection
KAPE Targets for Cloud Storage
# Collect all cloud storage artifacts using KAPE
kape.exe --tsource C: --tdest C:\Output\CloudArtifacts --target GoogleDrive,OneDrive,Dropbox,Box
# OneDrive artifacts
# %USERPROFILE%\AppData\Local\Microsoft\OneDrive\logs\
# %USERPROFILE%\AppData\Local\Microsoft\OneDrive\settings\
# %USERPROFILE%\OneDrive\
# Google Drive artifacts
# %USERPROFILE%\AppData\Local\Google\DriveFS\
# Contains metadata SQLite databases and cached files
# Dropbox artifacts
# %USERPROFILE%\AppData\Local\Dropbox\
# %USERPROFILE%\Dropbox\.dropbox.cache\
# Contains filecache.dbx (encrypted SQLite), host.dbx, config.dbx
OneDrive Local Database Analysis
import sqlite3
import os
def analyze_onedrive_sync_engine(db_path: str) -> list:
"""Analyze OneDrive SyncEngineDatabase for file metadata."""
conn = sqlite3.connect(db_path)
cursor = conn.cursor()
# Query for all tracked files including cloud-only items
cursor.execute("""
SELECT fileName, fileSize, lastChange,
resourceID, parentResourceID, eTag
FROM od_ClientFile_Records
ORDER BY lastChange DESC
""")
files = []
for row in cursor.fetchall():
files.append({
"filename": row[0],
"size": row[1],
"last_change": row[2],
"resource_id": row[3],
"parent_id": row[4],
"etag": row[5]
})
conn.close()
return files
Cloud Storage Artifacts Summary
| Service |
Local Database |
Cache Location |
Log Files |
| OneDrive |
SyncEngineDatabase.db |
%LOCALAPPDATA%\Microsoft\OneDrive\cache\ |
%LOCALAPPDATA%\Microsoft\OneDrive\logs\ |
| Google Drive |
metadata_sqlite_db |
%LOCALAPPDATA%\Google\DriveFS{account}\content_cache\ |
%LOCALAPPDATA%\Google\DriveFS\Logs\ |
| Dropbox |
filecache.dbx (encrypted) |
%APPDATA%\Dropbox.dropbox.cache\ |
%APPDATA%\Dropbox\logs\ |
| Box |
sync_db |
%LOCALAPPDATA%\Box\Box\cache\ |
%LOCALAPPDATA%\Box\Box\logs\ |
References
Example Output
$ python3 cloud_forensic_acquire.py --provider google-drive --auth /tokens/gdrive_token.json \
--user jsmith@corporate.com --output /acquisition/gdrive
Cloud Storage Forensic Acquisition Tool v3.2
==============================================
Provider: Google Drive
Account: jsmith@corporate.com
Start Time: 2024-01-19 08:00:15 UTC
Auth Method: Admin SDK (domain-wide delegation)
[+] Enumerating files...
Total files: 2,345
Total folders: 178
Shared with me: 456
Trashed items: 89 (included in acquisition)
Total size: 14.7 GB
[+] Acquiring file contents...
Downloaded: 2,345 / 2,345 [████████████████████████████████] 100%
Errors: 0
Elapsed: 18m 32s
[+] Acquiring metadata...
File metadata: 2,345 entries
Revision history: 8,912 revisions across 1,234 files
Sharing permissions: 3,456 permission entries
Activity log: 12,345 events
[+] Acquiring trashed items...
Recovered: 89 / 89 items (234 MB)
--- Acquisition Log ---
Timestamp (UTC) | Action | File | Size | SHA-256
2024-01-19 08:00:45 | Downloaded | /My Drive/Finance/Q4_Report.xlsm | 245 KB | 7a3b8c9d...
2024-01-19 08:00:46 | Downloaded | /My Drive/Finance/Budget_2024.xlsx | 1.2 MB | 8b4c9d0e...
...
2024-01-19 08:02:12 | Trash-Recovered | /Trash/employee_list_full.csv | 4.5 MB | 9c5d0e1f...
2024-01-19 08:02:13 | Trash-Recovered | /Trash/network_diagram_v3.vsdx | 2.1 MB | 0d6e1f2a...
2024-01-19 08:02:14 | Trash-Recovered | /Trash/credentials_backup.kdbx | 128 KB | 1e7f2a3b...
--- Sharing Analysis ---
Files Shared Externally:
/My Drive/Finance/Q4_Report.xlsm → j.smith.personal8842@protonmail.com (2024-01-16 03:10 UTC)
/My Drive/HR/employee_list_full.csv → j.smith.personal8842@protonmail.com (2024-01-16 03:12 UTC)
/My Drive/IT/network_diagram_v3.vsdx → anonymous (link sharing, 2024-01-16 03:15 UTC)
--- Revision History (Suspicious) ---
File: /My Drive/Finance/Q4_Report.xlsm
Rev 1: 2024-01-10 09:00:00 UTC (245 KB) - Original
Rev 2: 2024-01-15 14:35:00 UTC (248 KB) - Modified (macro added)
Rev 3: 2024-01-16 03:05:00 UTC (245 KB) - Reverted (macro removed - anti-forensics)
Acquisition Summary:
Files acquired: 2,345 (14.7 GB)
Trashed items: 89 (234 MB)
Revisions: 8,912
Chain of custody hash (full archive):
SHA-256: a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2
Output directory: /acquisition/gdrive/
Acquisition log: /acquisition/gdrive/acquisition_log.csv
Completion Time: 2024-01-19 08:18:47 UTC
Other files in this skill
assets/template.md (verbatim)
Cloud Storage Forensic Acquisition Report
| Field |
Value |
| Case Number |
|
| Examiner |
|
| Legal Authorization |
|
Cloud Services Identified
| Service |
Account |
Files Acquired |
Deleted Items |
Shared Items |
|
|
|
|
|
Acquisition Summary
| Method |
Files |
Size |
Hash Verified |
| API-Based |
|
|
|
| Endpoint Artifacts |
|
|
|
Findings
(Summary of cloud storage forensic analysis)
references/api-reference.md (verbatim)
API Reference: Cloud Storage Forensic Acquisition
Libraries Used
| Library |
Purpose |
boto3 |
AWS S3 object listing, download, and versioning |
json |
Parse object metadata and access logs |
hashlib |
Generate SHA-256 hashes for evidence integrity |
datetime |
Filter objects by time range for incident scope |
Installation
pip install boto3
Authentication
import boto3
import os
session = boto3.Session(
aws_access_key_id=os.environ.get("AWS_ACCESS_KEY_ID"),
aws_secret_access_key=os.environ.get("AWS_SECRET_ACCESS_KEY"),
region_name=os.environ.get("AWS_REGION", "us-east-1"),
)
s3 = session.client("s3")
AWS S3 Forensic Operations
List All Object Versions (Including Deleted)
def list_all_versions(bucket, prefix=""):
"""List all object versions including delete markers for forensic timeline."""
paginator = s3.get_paginator("list_object_versions")
versions = []
for page in paginator.paginate(Bucket=bucket, Prefix=prefix):
for v in page.get("Versions", []):
versions.append({
"key": v["Key"],
"version_id": v["VersionId"],
"last_modified": v["LastModified"].isoformat(),
"size": v["Size"],
"is_latest": v["IsLatest"],
"etag": v["ETag"],
})
for dm in page.get("DeleteMarkers", []):
versions.append({
"key": dm["Key"],
"version_id": dm["VersionId"],
"last_modified": dm["LastModified"].isoformat(),
"is_delete_marker": True,
"is_latest": dm["IsLatest"],
})
return sorted(versions, key=lambda v: v["last_modified"])
Download Object with Integrity Verification
import hashlib
def forensic_download(bucket, key, output_path, version_id=None):
"""Download an S3 object and compute SHA-256 hash for chain of custody."""
params = {"Bucket": bucket, "Key": key}
if version_id:
params["VersionId"] = version_id
resp = s3.get_object(**params)
sha256 = hashlib.sha256()
with open(output_path, "wb") as f:
for chunk in resp["Body"].iter_chunks(chunk_size=8192):
f.write(chunk)
sha256.update(chunk)
return {
"key": key,
"version_id": version_id,
"output_path": output_path,
"sha256": sha256.hexdigest(),
"content_type": resp.get("ContentType"),
"last_modified": resp["LastModified"].isoformat(),
"metadata": resp.get("Metadata", {}),
}
Recover Deleted Objects
def recover_deleted_objects(bucket, prefix=""):
"""Find and restore objects with delete markers."""
recovered = []
paginator = s3.get_paginator("list_object_versions")
for page in paginator.paginate(Bucket=bucket, Prefix=prefix):
for dm in page.get("DeleteMarkers", []):
if dm["IsLatest"]:
# Remove delete marker to restore the object
s3.delete_object(
Bucket=bucket,
Key=dm["Key"],
VersionId=dm["VersionId"],
)
recovered.append({
"key": dm["Key"],
"delete_marker_removed": dm["VersionId"],
})
return recovered
Get S3 Access Logs for Incident Timeline
def get_access_logs(log_bucket, prefix, start_time, end_time):
"""Parse S3 access logs to build forensic timeline."""
paginator = s3.get_paginator("list_objects_v2")
log_entries = []
for page in paginator.paginate(Bucket=log_bucket, Prefix=prefix):
for obj in page.get("Contents", []):
if start_time <= obj["LastModified"].isoformat() <= end_time:
resp = s3.get_object(Bucket=log_bucket, Key=obj["Key"])
content = resp["Body"].read().decode("utf-8")
for line in content.strip().split("\n"):
log_entries.append(line)
return log_entries
def acquire_bucket_metadata(bucket):
"""Collect all bucket configuration for forensic evidence."""
metadata = {"bucket": bucket}
metadata["versioning"] = s3.get_bucket_versioning(Bucket=bucket)
metadata["encryption"] = s3.get_bucket_encryption(Bucket=bucket).get(
"ServerSideEncryptionConfiguration", {}
)
try:
metadata["logging"] = s3.get_bucket_logging(Bucket=bucket).get("LoggingEnabled", {})
except Exception:
metadata["logging"] = None
try:
metadata["lifecycle"] = s3.get_bucket_lifecycle_configuration(Bucket=bucket).get("Rules", [])
except Exception:
metadata["lifecycle"] = []
try:
metadata["policy"] = json.loads(s3.get_bucket_policy(Bucket=bucket)["Policy"])
except Exception:
metadata["policy"] = None
return metadata
Evidence Chain of Custody
import json
from datetime import datetime, timezone
def create_chain_of_custody(evidence_items):
"""Generate a chain-of-custody record for acquired evidence."""
record = {
"acquisition_time": datetime.now(timezone.utc).isoformat(),
"examiner": os.environ.get("EXAMINER_NAME", "automated"),
"case_id": os.environ.get("CASE_ID", "unknown"),
"items": [],
}
for item in evidence_items:
record["items"].append({
"source": f"s3://{item['bucket']}/{item['key']}",
"local_path": item["output_path"],
"sha256": item["sha256"],
"acquired_at": datetime.now(timezone.utc).isoformat(),
})
return record
{
"bucket": "incident-bucket",
"acquisition_time": "2025-01-15T10:30:00Z",
"total_objects": 1542,
"total_versions": 3891,
"deleted_objects_recovered": 23,
"evidence_items": [
{
"key": "sensitive/data.csv",
"version_id": "abc123",
"sha256": "a1b2c3d4e5f6...",
"last_modified": "2025-01-14T08:00:00Z"
}
]
}
references/standards.md (verbatim)
Standards - Cloud Storage Forensic Acquisition
Standards
- NIST SP 800-86: Guide to Integrating Forensic Techniques
- ISO/IEC 27037: Digital Evidence Collection
- NIST Cloud Computing Forensic Science Challenges (NISTIR 8006)
- CSA Cloud Forensics Capability Implementation Guide
- Magnet AXIOM Cloud: Commercial multi-cloud acquisition
- Cellebrite Cloud Analyzer: SaaS evidence collection
- kumodd: Open-source proof-of-concept cloud acquisition tool
- KAPE: Endpoint-based cloud artifact collection
API References
references/workflows.md (verbatim)
Workflows - Cloud Storage Forensic Acquisition
Workflow 1: API-Based Remote Acquisition
Obtain legal authorization and credentials
|
Authenticate via service API (OAuth2 / app credentials)
|
Enumerate all files including shared and trashed items
|
Download file contents preserving metadata
|
Collect revision history and activity logs
|
Hash all acquired files (SHA-256)
|
Generate acquisition log with timestamps
Workflow 2: Endpoint Artifact Collection
Identify cloud sync client installations
|
Collect local sync databases (KAPE cloud targets)
|
Parse sync engine databases (OneDrive, GDrive, Dropbox)
|
Identify cloud-only files from metadata
|
Recover cached and deleted files from local storage
|
Correlate local artifacts with API-acquired data
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.