A Taxonomy of Cloud Endpoint Forensic Tools - Advances in Digital Forensics XIV Access content directly
Conference Papers Year : 2018

A Taxonomy of Cloud Endpoint Forensic Tools


Cloud computing services can be accessed via browsers or client applications on networked devices such as desktop computers, laptops, tablets and smartphones, which are generally referred to as endpoint devices. Data relevant to forensic investigations may be stored on endpoint devices and/or at cloud service providers. When cloud services are accessed from an endpoint device, several files and folders are created on the device; the data can be accessed by a digital forensic investigator using various tools. An investigator may also use an application programming interface made available by a cloud service provider to obtain forensic information from the cloud related to objects, events and file metadata associated with a cloud user. This chapter presents a taxonomy of the forensic tools used to extract data from endpoint devices and from cloud service providers. The tool taxonomy provides investigators with an easily searchable catalog of tools that can meet their technical requirements during cloud forensic investigations.
Fichier principal
Vignette du fichier
472401_1_En_14_Chapter.pdf (164.88 Ko) Télécharger le fichier
Origin : Files produced by the author(s)

Dates and versions

hal-01988833 , version 1 (22-01-2019)





Anand Kumar Mishra, Emmanuel Pilli, Mahesh Govil. A Taxonomy of Cloud Endpoint Forensic Tools. 14th IFIP International Conference on Digital Forensics (DigitalForensics), Jan 2018, New Delhi, India. pp.243-261, ⟨10.1007/978-3-319-99277-8_14⟩. ⟨hal-01988833⟩
87 View
249 Download



Gmail Facebook Twitter LinkedIn More