Blog >> iCloud

Investigating iCloud

14/05/2021 Friday

iCloud is an Apple Inc. cloud management and cloud computing application launched in October 2011. iCloud allows users to store, share, and send data, files, and documents among users and devices. iCloud is available for Windows, iOS, and macOS devices. In addition, iCloud wirelessly backs up iOS devices directly to iCloud. By connecting accounts via AirDrop wireless, service users are also able to exchange images, songs, and games instantly.

Digital Forensics Value of iCloud

Cloud computing has opened up new digital forensics challenges. iCloud file contains information about files that users upload and sync to iCloud, cloud data, when iCloud was enabled, when iCloud account was deleted, when iCloud data was deleted, and when the devices were wiped, and configuration. This information is critical during the forensic analysis process, as it helps us understand the types of artifacts that are likely to remain for digital forensics investigators.

Location of iCloud Artifacts

In Windows 10 iCloud artifacts are located at C:\Users\username\iCloudDrive

Structure of iCloud Artifacts

iCloud drive contains databases and plist files that store logs, cloud items, photos, albums, shared and local documents, and server items.

Analyzing iCloud Artifacts with ArtiFast Windows

This section will discuss how to use ArtiFast Windows to extract iCloud artifacts from Windows machines and what kind of digital forensics insight we can gain from the artifacts.

After you have created your case and added evidence for the investigation, at the Artifact Parser Selection Phase, you can select iCloud artifacts:

Once ArtiFast parser plugins complete processing the artifact for analysis, it can be reviewed via “Artifact View” or “Timeline View,” with indexing, filtering, and searching capabilities. Below is a detailed description of iCloud artifacts in ArtiFast software.

iCloud Drive Local Items Artifact

iCloud Drive Local Paths Artifact

iCloud Drive Local Shard Documents Artifact

iCloud Photos Album Assets Artifact

iCloud Photos Shared Albums Artifact

iCloud Photos Shared Asset Comments Artifact

iCloud Photos Timeline Events Artifact

iCloud Drive Server Items Artifact

iCloud Drive Server Shard Documents Artifact