Table of Contents
Fetching ...

What's Next, Cloud? A Forensic Framework for Analyzing Self-Hosted Cloud Storage Solutions

Michael Külper, Jan-Niclas Hilgert, Frank Breitinger, Martin Lambertz

TL;DR

This work tackles the forensic analysis of self-hosted cloud storage, focusing on Nextcloud to address the gap in mainstream cloud-forensics research. It proposes an extended framework that integrates API-based data acquisition and continuous monitoring to enable repeatable, evidence-rich investigations across both client and server components. The authors identify seven artifact classes, demonstrate how Nextcloud’s native APIs yield reliable artifacts, and release open-source tools to support API-driven acquisitions. The findings show that many artifacts persist across generations of self-hosted cloud platforms, underscoring the need for adaptive, monitoring-enabled forensic frameworks with practical tooling for real-world investigations.

Abstract

Self-hosted cloud storage platforms like Nextcloud are gaining popularity among individuals and organizations seeking greater control over their data. However, this shift introduces new challenges for digital forensic investigations, particularly in systematically analyzing both client and server components. Despite Nextcloud's widespread use, it has received limited attention in forensic research. In this work, we critically examine existing cloud storage forensic frameworks and highlight their limitations. To address the gaps, we propose an extended forensic framework that incorporates device monitoring and leverages cloud APIs for structured, repeatable evidence acquisition. Using Nextcloud as a case study, we demonstrate how its native APIs can be used to reliably access forensic artifacts, and we introduce an open-source acquisition tool that implements this approach. Our framework equips investigators with a more flexible method for analyzing self-hosted cloud storage systems, and offers a foundation for further development in this evolving area of digital forensics.

What's Next, Cloud? A Forensic Framework for Analyzing Self-Hosted Cloud Storage Solutions

TL;DR

This work tackles the forensic analysis of self-hosted cloud storage, focusing on Nextcloud to address the gap in mainstream cloud-forensics research. It proposes an extended framework that integrates API-based data acquisition and continuous monitoring to enable repeatable, evidence-rich investigations across both client and server components. The authors identify seven artifact classes, demonstrate how Nextcloud’s native APIs yield reliable artifacts, and release open-source tools to support API-driven acquisitions. The findings show that many artifacts persist across generations of self-hosted cloud platforms, underscoring the need for adaptive, monitoring-enabled forensic frameworks with practical tooling for real-world investigations.

Abstract

Self-hosted cloud storage platforms like Nextcloud are gaining popularity among individuals and organizations seeking greater control over their data. However, this shift introduces new challenges for digital forensic investigations, particularly in systematically analyzing both client and server components. Despite Nextcloud's widespread use, it has received limited attention in forensic research. In this work, we critically examine existing cloud storage forensic frameworks and highlight their limitations. To address the gaps, we propose an extended forensic framework that incorporates device monitoring and leverages cloud APIs for structured, repeatable evidence acquisition. Using Nextcloud as a case study, we demonstrate how its native APIs can be used to reliably access forensic artifacts, and we introduce an open-source acquisition tool that implements this approach. Our framework equips investigators with a more flexible method for analyzing self-hosted cloud storage systems, and offers a foundation for further development in this evolving area of digital forensics.
Paper Structure (53 sections, 1 figure, 3 tables)

This paper contains 53 sections, 1 figure, 3 tables.

Figures (1)

  • Figure 1: An improved cloud storage forensic framework including a new Monitoring phase