Taking instructions now — the first conversation is freeExhibits posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
FDRForensic Data Recovery 0800 6890668 Price my job
FDR / What the evidence can show / Cloud sync and webmail activity

Cloud sync · personal Dropbox · uploads · webmail · transfer sites · browser history

Cloud sync and webmail activity. A device records when a personal cloud client arrived, how much it uploaded, and the webmail and transfer sites visited, if not what was sent.

USB sticks are not the only way data leaves a computer, and the modern way is the cloud. A Windows computer records a good deal about it: when a personal cloud client, a personal Dropbox, Google Drive or OneDrive account rather than the company's, was installed; how much its logs show was uploaded and when; the browser history of sign-ins to webmail services and visits to file-transfer sites; and the absence of corresponding downloads, which is consistent with data going out rather than coming in. The standard report draws these together, and it is scrupulous about the limit, which matters here more than anywhere: these artefacts record the volume and timing of activity, that a client uploaded so many megabytes over an evening, that a transfer site was visited, not the contents of what was uploaded or sent. That limit is why the cloud picture is usually one strand among several, corroborated by the removable-media and deletion evidence, rather than a standalone proof.

Owner-only, authority requiredFree first conversationStandard report £800 + VATWe say what it cannot prove

Rather talk it through? An engineer answers the bench line
0800 6890668

Before anything else: stop using the device, and do not let anyone have a look at it. Every time a computer is switched on and used, the very artefacts an examination relies on, the timeline, the recently-opened lists, the deleted-file space, are overwritten a little more. Do not reinstall, do not run recovery software, do not let IT open it to check, and keep it powered off. Preserve it as it is, record who has held it, and send it with the authority documents we ask for. If proceedings are contemplated, the duty to preserve evidence has already begun.

What the device records about data going out.

A cloud client's installation is recorded in the installed-programs list and the Application event log, with a time, and the installer often remains in the Downloads folder. So the examination can show that a personal cloud client, distinct from the company's sanctioned one, appeared on the machine, and when, which in a departing-employee case is itself significant if it arrived in the final days.

The client's own log files record sync activity, including how much data was uploaded and when, though not, in general, the names of the files. Browser history records sign-ins to webmail services and visits to file-transfer websites, with times; and where visits to a transfer site are not accompanied by downloads in the browser's download history, that pattern is consistent with uploading rather than downloading.

The limit is fundamental and we never blur it: these artefacts show that data was uploaded and how much and when, not what was in it. An upload of 1.8 gigabytes over two evenings is a fact the report can state; that it contained the company's client list is an inference the report will not make from the cloud evidence alone. That is why the cloud strand is corroborated by the removable-media, folder-access and deletion evidence, and read as part of a whole.

What it records, and what it means.

Describe your situation →
What is recorded Where it comes from What it shows, and does not
A personal cloud client installedInstalled programs, Application log, DownloadsThat the client was installed and when; not what it synced
Upload volume and timingThe client's own log filesHow much was uploaded and when; not the file contents
Webmail and transfer-site visitsBrowser historyThat the sites were visited and when; not what was sent
Uploads without matching downloadsBrowser download history, by absenceA pattern consistent with uploading; not proof of content

From the exhibit arriving to the report.

Work we have closed →
01

The first conversation, and the authority check Free

Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.

FreeOwner-only; authority established firstThe honest answer about what is possible
02

Imaging behind a write blocker, and the hashes

When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.

Bit-for-bit, behind a write blockerMD5 and SHA-256, verifiedThe original never altered
03

The examination, on the image

The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.

Scoped to your questionsConfirmed in a second toolPrivate material filtered out
04

The report

The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.

Factual, tool-generated, self-containedChain-of-custody and case-log reports5–10 working days

From the bench

  • Preserve the machine; browser history and client logs can be cleared or roll over with continued use.
  • Read the cloud evidence with the rest; it is strongest corroborated by removable-media and deletion findings.
  • Do not overstate it; volume and timing are evidence, content is not, and a report that claims otherwise invites challenge.

Upload volume and timing are recorded in a cloud client's logs; the contents of what was uploaded are not, and a sound report never claims otherwise.

What helps, and what harms.

Do this much first

  • Stop using the device and keep it powered off
  • Preserve it as it is; record who has held it
  • Gather your proof of ownership or authority
  • Tell us the questions you need answered

What sets us back

  • Letting IT or anyone open it to have a look
  • Reinstalling, wiping or running recovery software
  • Carrying on using the device
  • Assuming artefacts prove who was at the keyboard
We examine devices only for the people and organisations with lawful authority over them. Before any work begins we ask for proof that the device is yours, or documented authority to have it examined: proof of ownership, a director's or HR letter for a company device with the lawful basis, a solicitor's instruction, a court order, or an executor's grant. It is a condition of the work, not a formality, and it is what keeps the examination on the right side of the Computer Misuse Act 1990. We will not access another adult's device or accounts without their consent or a court order, we will not install monitoring software or bypass anyone's security, and we do not undertake covert surveillance. A device with no proof of authority is returned unexamined.

Questions answered before you instruct.

Can you tell what was uploaded to the cloud?

No. The cloud client's logs record how much was uploaded and when, not the names or contents of the files. The report states the upload volume and timing as fact, and does not claim to know what was in an upload. That candour is what keeps the evidence credible, and it is why the cloud strand is read alongside the removable-media and deletion evidence.

Is a personal cloud client on a work laptop significant?

It can be, particularly if it was installed in the final days before an employee left and its logs show substantial uploads. The report sets out when it was installed and how much it uploaded; what that signifies is a matter for you and your solicitor, with the other evidence.

Can you get into the employee's cloud account to see the files?

No. The cloud account belongs to the employee, and accessing it would need their authority or a court order. We examine what the device records about the client and its activity, not the account's contents.

How do you know data went out rather than came in?

Where the browser shows visits to a transfer site or uploads by a cloud client, but no corresponding entries in the browser's download history, the pattern is consistent with data going out. We describe it as consistent with uploading, not as proof, because that is what the evidence supports.

What does it cost?

Cloud and webmail activity is part of the standard forensic report, £800 + VAT for a one-disk system. The first conversation is free.

The record is on the device; preserve it first.

The first conversation is free. Tell us the situation and who owns the device, and we will tell you what the evidence can show, what it cannot, and whether we can take it on. Until then, stop using the device and preserve it as it is.

0800 6890668