ServingNew York, New Jersey, and Connecticut
24/7 incident response1-800-868-8189Contact GDF

Cloud tenants / SaaS / hyperscalers

Cloud forensics: Microsoft 365, Google Workspace, AWS, Azure and GCP

Reviewed on .

Preserve and analyze cloud tenant activity: Microsoft 365 and Google Workspace audit logs, mailbox and drive content, admin console changes, and AWS / Azure / GCP account activity.

Get a free consultation
Chain-of-custody workflow from source identification through preservation, examination, and reporting
Cloud tenant audit-log export coordinated with the client IT provider before any production change.

Cloud examinations require an early conversation about what the tenant retains by default, what has to be exported before the retention window closes, and which admin credentials can authorize the collection. We coordinate that with counsel and the IT provider before touching production.

Common scopes: mailbox and drive preservation with audit-log export, tenant configuration snapshots, admin-consent and MFA activity, license-based access history, and cross-tenant sharing activity. Also see cloud and SaaS forensics and cloud and SaaS expert witness.

For breach matters where a cloud tenant is one of several sources, pair with incident response and NYDFS cybersecurity evidence.

Discuss this matter with GDF

Confidential intake reviewed by a New York examiner. Reference the deadline, the devices or accounts involved, and how counsel or IT wants to receive the initial call.

Prefer email? Use gdfleads@evestigate.com. 24/7 line: 877.504.3580.

Include deadline and evidence type. Do not paste passwords, health data, payment data, or government identification.

Screened via Cloudflare Turnstile.