Cloud and Email Forensics

Valkyrie investigates Microsoft 365, Google Workspace, email and cloud storage accounts, including logins, forwarding rules and file sharing. More and more evidence never touches a local device: it lives in the cloud, and the records showing who did what can disappear quickly.

What the records reveal

  • When and from where an account was accessed
  • Hidden forwarding and inbox rules that quietly copy or delete email
  • Files shared externally, downloaded or synced to other devices
  • Email headers showing where a message really came from
  • Changes to account settings, passwords and security methods

Business email compromise and invoice fraud

When a supplier’s bank details are changed or a payment is diverted, the mailbox and sign-in logs usually show how the attacker got in and what they saw. We establish the facts for insurers, lawyers and recovery action, working with our cyber security team where the threat is still live.

Departing employees and data leaks

Cloud audit logs can show documents being forwarded to personal accounts or downloaded in bulk shortly before someone leaves, which is often key evidence in injunction applications.

Why speed matters

How far back do the logs go?

It depends on the service and licence, and in some cases the record is short. Contact us as soon as you suspect a problem so that logs can be preserved before they expire.

Do we need the account password?

Usually we work with an administrator from your organisation. We will explain exactly what access is needed and why.

See all our digital forensics services, or contact us in confidence.

Valkyrie Updates

News

Stay informed with the latest insights, expertise and innovations in the world of security with Valkyrie’s news, reports and white papers